Where
AND
-Infinity
0
Severity
3.8
Input Validation
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-f6M7cs6r

First published (updated )
Severity
1
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient access controls to a shared memory resource. An attacker could exploit this vulnerability by corrupting a shared memory segment on an affected device. A successful exploit could allow the attacker to cause the device to reload. The device will recover from the corruption upon reboot. After additional investigation it was determined that this vulnerability is not exploitable in production software. Cisco has provided software updates for this issue. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tpce-rmos-mem-dos-rck56tT

First published (updated )
Severity
3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

A flaw was found in the Linux kernel's wifi implementation wherein an attacker within wireless range is able to abuse a logic flaw in the wifi implementation by reassembling packets from multiple fragments under different keys and they would be treated as valid. This allows an attacker to send a fragment under an incorrect key and be treated as a valid fragment under the new key.

Upstream patch: https://lore.kernel.org/linux-wireless/20210511200110.3f8290e59823.I622a67769ed39257327a362cfc09c812320eb979@changeid/

1 / 4
Source: Red Hat

Remedy

Mitigation for this issue is either not available or the currently available options does not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
First published (updated )
Severity
1
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

The Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software supports the relay of media connections through a firewall using proxy services. As a result of this feature, interfaces such as the Cisco Expressway web administrative interface may become accessible from external networks. At the time of publication, documentation of the feature did not properly explain that users are able to bypass firewall protections that are designed to restrict access to the Cisco Expressway web administrative interface. However, an attacker must have credentials sufficient to use TURN services to be able to send network requests to the web administrative interface. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-Expressway-8J3yZ7hV

First published (updated )
Severity
3.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of CLI command parameters. An attacker could exploit this vulnerability by executing specific commands on the local-mgmt CLI on an affected device. A successful exploit could allow the attacker to cause internal system processes to fail to terminate properly, which could result in a buildup of stuck processes and lead to slowness in accessing the UCS Manager CLI and web UI. A sustained attack may result in a restart of internal UCS Manager processes and a temporary loss of access to the UCS Manager CLI and web UI. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-cli-dos-GQUxCnTe

First published (updated )
Severity
3.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An authenticated, remote attacker could exploit this vulnerability by using the host role to share files within the Multimedia sharing feature and convincing a former room host to view that file. A warning dialog normally appears cautioning users before the file is displayed; however, the former host would not see that warning dialog, and any shared multimedia would be rendered within the user's browser. The attacker could leverage this behavior to conduct additional attacks by including malicious files within a targeted room host's browser window.

First published (updated )
Severity
1
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N

Cisco TelePresence Management Suite (TMS) software implements a Simple Object Access Protocol (SOAP) interface that by design allows unauthenticated access to web services designed to provide management features to devices. At first publication of the advisory, the management feature was not documented and may have represented unknown risks to customers implementing the feature within their environments. Customers should refer to page 18 of the Cisco TMS Admin Guide for additional information that documents the management feature.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-tms-soap

First published (updated )
Severity
3.3
Infoleak
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted system. The vulnerability is due to insufficient security restrictions. An attacker could exploit this vulnerability by accessing unauthorized information within the ConfD directory and file structure. Successful exploitation could allow the attacker to view sensitive information. Cisco Bug IDs: CSCvg00221.

First published (updated )
Severity
1
Buffer Overflow
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp

1 / 2
Source: Cisco

Remedy

<p>Administrators are advised to allow only trusted users to have SNMP access on an affected system. Administrators are also advised to monitor affected systems by using the <strong>show snmp host</strong> command in the CLI.</p> <p>In addition, administrators can mitigate these vulnerabilities by disabling the following MIBs on a device:</p> <ul> <li>ADSL-LINE-MIB</li> <li>ALPS-MIB</li> <li>CISCO-ADSL-DMT-LINE-MIB</li> <li>CISCO-AUTH-FRAMEWORK-MIB</li> <li>CISCO-BSTUN-MIB</li> <li>CISCO-MAC-AUTH-BYPASS-MIB</li> <li>CISCO-SLB-EXT-MIB</li> <li>CISCO-VOICE-DNIS-MIB</li> <li>CISCO-VOICE-NUMBER-EXPANSION-MIB</li> <li>TN3270E-RT-MIB</li> </ul> <p>To create or update a view entry and disable the affected MIBs, administrators can use the <strong>snmp-server view</strong> global configuration command, as shown in the following example:</p> <blockquote> <pre>!Standard VIEW and Security Exclusions<br>snmp-server view NO_BAD_SNMP iso included<br>snmp-server view NO_BAD_SNMP internet included<br>snmp-server view NO_BAD_SNMP snmpUsmMIB excluded<br>snmp-server view NO_BAD_SNMP snmpVacmMIB excluded<br>snmp-server view NO_BAD_SNMP snmpCommunityMIB excluded<br>snmp-server view NO_BAD_SNMP ciscoMgmt.252 excluded<br>!End Standard View <br><br>!Advisory Specific Mappings<br>!ADSL-LINE-MIB<br>snmp-server view NO_BAD_SNMP transmission.94 excluded <br><br>!TN3270E-RT-MIB<br>snmp-server view NO_BAD_SNMP mib-2.34.9 excluded <br><br>!CISCO-BSTUN-MIB<br>snmp-server view NO_BAD_SNMP ciscoMgmt.35 excluded <br><br>!ALPS-MIB<br>snmp-server view NO_BAD_SNMP ciscoMgmt.95 excluded <br><br>!CISCO-ADSL-DMT-LINE-MIB<br>snmp-server view NO_BAD_SNMP ciscoMgmt.130 excluded <br><br>!CISCO-AUTH-FRAMEWORK-MIB<br>snmp-server view NO_BAD_SNMP ciscoAuthFrameworkMIB excluded<br><br>!CISCO-VOICE-DNIS-MIB<br>snmp-server view NO_BAD_SNMP ciscoMgmt.219 excluded <br><br>!CISCO-SLB-EXT-MIB<br>snmp-server view NO_BAD_SNMP ciscoMgmt.254 excluded <br><br>!CISCO-MAC-AUTH-BYPASS-MIB<br>snmp-server view NO_BAD_SNMP ciscoMabMIB excluded <br><br>!CISCO-VOICE-NUMBER-EXPANSION-MIB<br>snmp-server view NO_BAD_SNMP ciscoExperiment.997 excluded</pre> </blockquote> <p>To then apply this configuration to a community string, administrators can use the following command:</p> <blockquote> <pre>snmp-server community mycomm view NO_BAD_SNMP RO</pre> </blockquote> <p>For SNMP Version 3, administrators can use the following command:</p> <blockquote> <pre>snmp-server group v3group auth read NO_BAD_SNMP write NO_BAD_SNMP</pre> </blockquote> <br>
First published (updated )
Severity
1
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C

Remedy

Administrators can restrict the Docker Engine port to bind to localhost (127.0.0.1) following the procedure below:<br> <br> <ol> <li>Issue the <strong>su</strong> command to obtain <em>sudo</em> privileges</li> <li>Enter the <em>system</em> directory using the following command <strong>cd /etc/systemd/system/</strong></li> <li>Edit the <em>docker.socket </em>file with your chosen editor and change the <em>ListenStream</em> value to the following:</li> <blockquote> <p>ListenStream=127.0.0.1:2375 </p> </blockquote> <li>Reload with the <strong>systemctl daemon-reload &amp;&amp; systemctl restart docker </strong>command</li> </ol> In addition, administrators can use the cloud provider security group or external firewall devices in private cloud deployment to restrict access to the CCO Docker Engine management port as per product documentation:<br> <a href="http://docs.cliqr.com/display/CCD46/Phase+2%3A+Configure+Network+Rules">http://docs.cliqr.com/display/CCD46/Phase+2%3A+Configure+Network+Rules</a><br>
First published (updated )
Severity
1
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:U/RC:C

Remedy

The administrator can set the LAN config mode to Ethernet Switch. This configuration setting can help avoid the unexpected controller reset due to TCP congestion on the management port. The unexpected reset has been observed only with the MSM configuration setting.
First published (updated )
Severity
1
Infoleak
AV:N/AC:L/Au:S/C:P/I:N/A:N/E:F/RL:OF/RC:C
First published (updated )
Severity
1
XSS
AV:N/AC:M/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C
First published (updated )
Severity
1
Input Validation
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C
First published (updated )
Severity
2.5
Input Validation
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system. This vulnerability affects the following products if they are running a vulnerable release of Cisco IOS XE Software: Cisco 5700 Series Wireless LAN Controllers, Cisco Catalyst 3650 Series Switches, Cisco Catalyst 3850 Series Switches, Cisco Catalyst 4500E Series Switches, Cisco Catalyst 4500X Series Switches. More Information: CSCva60013 CSCvb22622. Known Affected Releases: 3.7(0) 16.4.1 Denali-16.1.3 Denali-16.2.2 Denali-16.3.1. Known Fixed Releases: 15.2(4)E3 16.1(2.208) 16.2(2.42) 16.3(1.22) 16.4(0.190) 16.5(0.29).

First published (updated )
Severity
1
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
First published (updated )
Severity
1
AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C

Remedy

To work around and help prevent the effects of an attempt to exploit this vulnerability, administrators can change the maximum transmission unit (MTU) configuration on one or more internal interfaces for an affected device. Note that this workaround will not persist if a card is rebooted. If a card is rebooted, the MTU configuration must be changed again. For information about implementing this workaround, please contact the Cisco Technical Assistance Center (TAC).
First published (updated )
Severity
1
SQL Injection
AV:N/AC:M/Au:S/C:P/I:P/A:N/E:F/RL:U/RC:C
First published (updated )
Severity
1
AV:N/AC:M/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C
First published (updated )
Severity
1
Buffer Overflow
AV:N/AC:L/Au:S/C:N/I:N/A:C/E:F/RL:U/RC:C
First published (updated )
Severity
1
Input Validation
AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
First published (updated )
Severity
2.1
Infoleak
AV:L/AC:L/Au:N/C:P/I:N/A:N

Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203