Cisco

Connected Mobile Experiences

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 94.44%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.06.2025 17:29:54

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Warnung Exploit
  • EPSS 94.36%
  • Veröffentlicht 10.12.2021 10:15:09
  • Zuletzt bearbeitet 08.08.2025 18:52:00

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An atta...

  • EPSS 0.12%
  • Veröffentlicht 04.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:44:32

A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are conf...

  • EPSS 0.13%
  • Veröffentlicht 13.01.2021 22:15:14
  • Zuletzt bearbeitet 21.11.2024 05:43:41

A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorization checks for certain API GET r...

  • EPSS 0.46%
  • Veröffentlicht 13.01.2021 22:15:14
  • Zuletzt bearbeitet 21.11.2024 05:43:41

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due to incorrect handling of auth...

  • EPSS 0.05%
  • Veröffentlicht 26.08.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:30:25

A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CLI. The vulnerability is due to insufficient security mechanisms in the...

  • EPSS 0.02%
  • Veröffentlicht 26.08.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:30:26

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissions that ar...

  • EPSS 0.08%
  • Veröffentlicht 24.01.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:37:00

A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms ...