|
222041
|
5.3 |
MEDIUM
Local
|
cisco
|
enterprise_nfv_infrastructure_software
|
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to access the shell of the underlying Linux operating system on the aff…
|
CWE-20
Improper Input Validation
|
CVE-2019-1656
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222042
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings_server
|
A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-1655
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222043
|
8.0 |
HIGH
Adjacent
|
cisco
|
vsmart_controller sd-wan
|
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability…
|
CWE-284
Improper Access Control
|
CVE-2019-1647
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222044
|
7.5 |
HIGH
Network
|
cisco
|
rv320_firmware rv325_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to retrieve sensitive inform…
|
CWE-200
Information Exposure
|
CVE-2019-1653
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222045
|
7.2 |
HIGH
Network
|
cisco
|
rv320_firmware rv325_firmware
|
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges…
|
CWE-78
OS Command
|
CVE-2019-1652
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222046
|
8.8 |
HIGH
Network
|
cisco
|
vsmart_controller
|
A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a denial of service (DoS) condition and execute arbitrary code as the root user. …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-1651
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222047
|
8.8 |
HIGH
Network
|
cisco
|
vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vbond_orchestrator vsmart_controller vmanage_network_management sd-wan
|
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is …
|
CWE-78
OS Command
|
CVE-2019-1650
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222048
|
7.8 |
HIGH
Local
|
cisco
|
vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vbond_orchestrator vsmart_controller vmanage_network_management sd-wan
|
A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due t…
|
CWE-20
Improper Input Validation
|
CVE-2019-1648
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222049
|
7.8 |
HIGH
Local
|
cisco
|
vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vbond_orchestrator vsmart_controller vmanage_network_management sd-wan
|
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists becau…
|
CWE-77
Command Injection
|
CVE-2019-1646
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222050
|
4.3 |
MEDIUM
Adjacent
|
cisco
|
connected_mobile_experiences
|
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to …
|
CWE-200
Information Exposure
|
CVE-2019-1645
|
2024-11-21 13:37 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|