|
222091
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …
|
CWE-20
Improper Input Validation
|
CVE-2019-1817
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222092
|
7.8 |
HIGH
Local
|
cisco
|
web_security_appliance
|
A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. T…
|
CWE-20
Improper Input Validation
|
CVE-2019-1816
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222093
|
8.8 |
HIGH
Network
|
cisco
|
umbrella
|
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user sessio…
|
CWE-384
Session Fixation
|
CVE-2019-1807
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222094
|
9.8 |
CRITICAL
Network
|
cisco
|
nexus_9332pq_firmware nexus_93180yc-ex_firmware nexus_93128tx_firmware nexus_93120tx_firmware nexus_93108tc-ex_firmware nexus_9516_firmware nexus_9508_firmware nexus_9504_firmwar…
|
A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to t…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-1804
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222095
|
6.7 |
MEDIUM
Local
|
cisco
|
nexus_9000_series_application_centric_infrastructure
|
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administra…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-1803
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222096
|
8.8 |
HIGH
Network
|
cisco
|
rv325_dual_wan_gigabit_vpn_router_firmware rv320_dual_gigabit_wan_vpn_router_software
|
A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacke…
|
CWE-287
Improper Authentication
|
CVE-2019-1724
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222097
|
7.5 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_device_manager firepower_threat_defense
|
A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), used in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Thre…
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2019-1715
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222098
|
8.6 |
HIGH
Network
|
cisco
|
firepower_threat_defense adaptive_security_appliance_software
|
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 Single Sign-On (SSO) for Clientless SSL VPN (WebVPN) and AnyConnect Remote Access VPN in Cisco Adaptive Security…
|
NVD-CWE-Other
|
CVE-2019-1714
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222099
|
8.8 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software
|
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF…
|
CWE-352
Origin Validation Error
|
CVE-2019-1713
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222100
|
8.6 |
HIGH
Network
|
cisco
|
firepower_threat_defense adaptive_security_appliance_software
|
A vulnerability in the Internet Key Exchange Version 2 Mobility and Multihoming Protocol (MOBIKE) feature for the Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-1708
|
2024-11-21 13:37 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|