|
198861
|
7.5 |
HIGH
Network
|
cisco
|
ios
|
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected devi…
|
NVD-CWE-noinfo
|
CVE-2017-12234
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198862
|
7.5 |
HIGH
Network
|
cisco
|
ios
|
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected devi…
|
NVD-CWE-noinfo
|
CVE-2017-12233
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198863
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios
|
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent att…
|
NVD-CWE-noinfo
|
CVE-2017-12232
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198864
|
7.5 |
HIGH
Network
|
cisco
|
ios
|
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (D…
|
NVD-CWE-noinfo
|
CVE-2017-12231
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198865
|
8.8 |
HIGH
Network
|
cisco
|
ios_xe
|
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due…
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-12230
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198866
|
9.8 |
CRITICAL
Network
|
cisco
|
ios_xe
|
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of t…
|
CWE-287
Improper Authentication
|
CVE-2017-12229
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198867
|
5.9 |
MEDIUM
Network
|
cisco
|
ios ios_xe
|
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized ac…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-12228
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198868
|
8.8 |
HIGH
Network
|
cisco
|
ios_xe
|
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco Ne…
|
CWE-20
Improper Input Validation
|
CVE-2017-12226
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198869
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios_xe
|
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition…
|
CWE-20
Improper Input Validation
|
CVE-2017-12222
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198870
|
9.8 |
CRITICAL
Network
|
apache
|
commons_jelly
|
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser insta…
|
CWE-611
XXE
|
CVE-2017-12621
|
2024-11-21 12:09 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|