Cisco

Ios Xe

554 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Published 25.09.2019 20:15:10
  • Last modified 21.11.2024 04:23:15

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerabili...

  • EPSS 1.16%
  • Published 25.09.2019 20:15:10
  • Last modified 21.11.2024 04:23:15

A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory st...

  • EPSS 0.03%
  • Published 25.09.2019 20:15:10
  • Last modified 21.11.2024 04:23:15

A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists becaus...

  • EPSS 13.42%
  • Published 25.09.2019 20:15:10
  • Last modified 21.11.2024 04:23:15

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabili...

  • EPSS 23.97%
  • Published 28.08.2019 19:15:10
  • Last modified 21.11.2024 04:23:14

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check perfo...

  • EPSS 2.81%
  • Published 21.08.2019 19:15:13
  • Last modified 21.11.2024 04:23:12

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an ...

  • EPSS 0.59%
  • Published 21.06.2019 03:15:09
  • Last modified 21.11.2024 04:37:39

A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protectio...

  • EPSS 0.92%
  • Published 13.05.2019 20:29:03
  • Last modified 21.11.2024 04:37:33

A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs bec...

  • EPSS 0.23%
  • Published 13.05.2019 19:29:01
  • Last modified 21.11.2024 04:37:00

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulner...

  • EPSS 1%
  • Published 28.03.2019 01:29:00
  • Last modified 21.11.2024 04:37:17

A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation...