|
247331
|
9.8 |
CRITICAL
Network
|
cisco
|
ultra_services_framework
|
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (…
|
CWE-532 CWE-522
Inclusion of Sensitive Information in Log Files Insufficiently Protected Credentials
|
CVE-2017-6709
|
2024-11-21 12:30 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247332
|
9.8 |
CRITICAL
Network
|
cisco
|
ultra_services_framework
|
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive file…
|
CWE-200
Information Exposure
|
CVE-2017-6708
|
2024-11-21 12:30 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247333
|
8.2 |
HIGH
Local
|
cisco
|
staros
|
A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Cor…
|
CWE-78
OS Command
|
CVE-2017-6707
|
2024-11-21 12:30 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247334
|
6.1 |
MEDIUM
Network
|
cisco
|
prime_infrastructure
|
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interf…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6725
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247335
|
6.1 |
MEDIUM
Network
|
cisco
|
prime_infrastructure
|
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interf…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6724
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247336
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_contact_center_express
|
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legi…
|
CWE-287
Improper Authentication
|
CVE-2017-6722
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247337
|
5.3 |
MEDIUM
Network
|
cisco
|
wide_area_application_services
|
A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to rest…
|
CWE-20
Improper Input Validation
|
CVE-2017-6721
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247338
|
6.7 |
MEDIUM
Local
|
cisco
|
ios_xr
|
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection…
|
CWE-20
Improper Input Validation
|
CVE-2017-6719
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247339
|
6.7 |
MEDIUM
Local
|
cisco
|
ios_xr
|
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.…
|
CWE-20
Improper Input Validation
|
CVE-2017-6718
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247340
|
5.4 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interf…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6717
|
2024-11-21 12:30 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|