|
248101
|
8.8 |
HIGH
Network
|
cisco
|
network_level_service
|
A vulnerability in the web-based management interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and pe…
|
CWE-352
Origin Validation Error
|
CVE-2018-0446
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248102
|
8.8 |
HIGH
Network
|
cisco
|
packaged_contact_center_enterprise
|
A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary action…
|
CWE-352
Origin Validation Error
|
CVE-2018-0445
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248103
|
6.1 |
MEDIUM
Network
|
cisco
|
packaged_contact_center_enterprise
|
A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a stored XSS attack against a user of the …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0444
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248104
|
7.2 |
HIGH
Network
|
cisco
|
data_center_network_manager
|
A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands on the underlying operating system with root-level…
|
CWE-20
Improper Input Validation
|
CVE-2018-0440
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248105
|
8.8 |
HIGH
Network
|
cisco
|
meeting_server
|
A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitra…
|
CWE-352
Origin Validation Error
|
CVE-2018-0439
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248106
|
7.8 |
HIGH
Local
|
cisco
|
umbrella_enterprise_roaming_client
|
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker m…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0438
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248107
|
7.8 |
HIGH
Local
|
cisco
|
umbrella_enterprise_roaming_client umbrella_roaming_module
|
A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker m…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0437
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248108
|
8.7 |
HIGH
Network
|
cisco
|
webex_teams
|
A vulnerability in Cisco Webex Teams, formerly Cisco Spark, could allow an authenticated, remote attacker to view and modify data for an organization other than their own organization. The vulnerabil…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0436
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248109
|
9.1 |
CRITICAL
Network
|
cisco
|
umbrella
|
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insuffic…
|
CWE-287
Improper Authentication
|
CVE-2018-0435
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248110
|
7.4 |
HIGH
Network
|
cisco
|
vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vmanage_network_management_system
|
A vulnerability in the Zero Touch Provisioning feature of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid c…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0434
|
2024-11-21 12:38 |
2018-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|