|
221611
|
7.5 |
HIGH
Network
|
cisco
|
firepower_management_center firepower_threat_defense
|
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote att…
|
CWE-693
Protection Mechanism Failure
|
CVE-2019-1970
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221612
|
4.9 |
MEDIUM
Network
|
cisco
|
enterprise_network_function_virtualization_infrastructure
|
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected de…
|
CWE-20
Improper Input Validation
|
CVE-2019-1961
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221613
|
8.8 |
HIGH
Network
|
cisco
|
hyperflex_hx_data_platform
|
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected …
|
CWE-352
Origin Validation Error
|
CVE-2019-1958
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221614
|
7.5 |
HIGH
Network
|
cisco
|
iot_field_network_director
|
A vulnerability in the web interface of Cisco IoT Field Network Director could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition on…
|
NVD-CWE-noinfo
|
CVE-2019-1957
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221615
|
4.8 |
MEDIUM
Network
|
cisco
|
spa112_2-port_phone_adapter_firmware
|
A vulnerability in the web-based interface of the Cisco SPA112 2-Port Phone Adapter could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user o…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1956
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221616
|
7.5 |
HIGH
Network
|
cisco
|
email_security_appliance_firmware
|
A vulnerability in the Sender Policy Framework (SPF) functionality of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass config…
|
CWE-20
Improper Input Validation
|
CVE-2019-1955
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221617
|
7.8 |
HIGH
Local
|
cisco
|
adaptive_security_appliance_software
|
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a mal…
|
CWE-20
Improper Input Validation
|
CVE-2019-1945
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221618
|
7.3 |
HIGH
Local
|
cisco
|
adaptive_security_appliance_software
|
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a mal…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1944
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221619
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings_server
|
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerab…
|
CWE-20
Improper Input Validation
|
CVE-2019-1954
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221620
|
6.5 |
MEDIUM
Network
|
cisco
|
enterprise_network_function_virtualization_infrastructure
|
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to i…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-1953
|
2024-11-21 13:37 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|