|
221761
|
7.1 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to use symbolic links to …
|
CWE-59
Link Following
|
CVE-2019-1836
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221762
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
|
CWE-20
Improper Input Validation
|
CVE-2019-1817
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221763
|
7.8 |
HIGH
Local
|
cisco
|
web_security_appliance
|
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. T…
|
CWE-20
Improper Input Validation
|
CVE-2019-1816
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221764
|
8.8 |
HIGH
Network
|
cisco
|
umbrella
|
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user sessio…
|
CWE-384
Session Fixation
|
CVE-2019-1807
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221765
|
9.8 |
CRITICAL
Network
|
cisco
|
nexus_9332pq_firmware nexus_93180yc-ex_firmware nexus_93128tx_firmware nexus_93120tx_firmware nexus_93108tc-ex_firmware nexus_9516_firmware nexus_9508_firmware nexus_9504_firmwar…
|
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to t…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-1804
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221766
|
6.7 |
MEDIUM
Local
|
cisco
|
nexus_9000_series_application_centric_infrastructure
|
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administra…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1803
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221767
|
8.8 |
HIGH
Network
|
cisco
|
rv325_dual_wan_gigabit_vpn_router_firmware rv320_dual_gigabit_wan_vpn_router_software
|
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacke…
|
CWE-287
Improper Authentication
|
CVE-2019-1724
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221768
|
7.5 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_device_manager firepower_threat_defense
|
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre…
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2019-1715
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221769
|
8.6 |
HIGH
Network
|
cisco
|
firepower_threat_defense adaptive_security_appliance_software
|
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security…
|
NVD-CWE-Other
|
CVE-2019-1714
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221770
|
8.8 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software
|
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF…
|
CWE-352
Origin Validation Error
|
CVE-2019-1713
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|