PatchSiren

Cisco CVE debriefs · Page 10

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3845

Cisco Prime Collaboration Assurance contains a cross-site scripting (XSS) flaw in its web-based management interface. An unauthenticated remote attacker could trigger the issue against a user of the interface. Cisco lists versions 11.0, 11.1, and 11.5 as affected; versions prior to 11.0 are not vulnerable.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3844

CVE-2017-3844 is an authenticated remote information-disclosure issue in Cisco Prime Collaboration Assurance. According to Cisco and NVD, the affected UI exporting functions could let a logged-in attacker view directory listings and download files in vulnerable releases.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3843

CVE-2017-3843 is an access-control weakness in Cisco Prime Collaboration Assurance file download functions. An authenticated remote attacker could download system files that should have remained restricted. Cisco/NVD published the issue on 2017-02-22, and NVD rates it Medium with CVSS 4.3.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3842

CVE-2017-3842 is an information disclosure issue in the Cisco Intrusion Prevention System Device Manager (IDM) web management interface. According to the CVE record, an unauthenticated remote attacker could view sensitive information stored in certain HTML comments. The supplied NVD data assigns CVSS 3.0 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, reflecting a network-reachable confidentiality issue with [truncated]

HIGH Cisco CVE published 2017-02-22

CVE-2017-3841

CVE-2017-3841 affects the Cisco Secure Access Control System (ACS) web interface and can expose sensitive information to an unauthenticated remote attacker. The supplied NVD data rates the issue as CVSS 3.0 7.5 (HIGH) with a network attack vector and no privileges or user interaction required.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3840

CVE-2017-3840 is an open redirect vulnerability in the web interface of Cisco Secure Access Control System (ACS). According to the CVE record, an unauthenticated remote attacker could redirect a user to a malicious web page. Cisco identifies the issue in ACS 5.8(2.5), and NVD classifies it as CWE-601 with a CVSS 3.0 score of 6.1 (Medium).

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3839

CVE-2017-3839 is an XML External Entity (XXE) vulnerability in the web-based user interface of Cisco Secure Access Control System (ACS). Cisco and NVD describe the impact as read access to part of the information stored on the affected system. The NVD record classifies the issue as CVSS 3.0 4.3 (MEDIUM) and maps it to CWE-611. The affected release called out in the supplied data is ACS 5.8(2.5).

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3838

CVE-2017-3838 is a medium-severity DOM-based cross-site scripting flaw in Cisco Secure Access Control System (ACS). According to the CVE/NVD record, an unauthenticated remote attacker could trigger XSS in the web interface and affect a user of the system. The record lists Cisco Secure Access Control System 5.8(2.5) as the known affected release and classifies the weakness as CWE-79.

HIGH Cisco CVE published 2017-02-22

CVE-2017-3837

CVE-2017-3837 is a Cisco Meeting Server Web Bridge vulnerability that can let an authenticated remote attacker with a valid Web Bridge session retrieve memory contents and potentially crash the application. The main risk is disclosure of confidential information, with an additional availability impact from an unexpected denial of service. Cisco and NVD list affected releases prior to 2.1.2, including 2.0 [truncated]

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3836

CVE-2017-3836 is a Cisco Unified Communications Manager web-framework issue that can expose sensitive data to a remote attacker. The NVD record classifies the issue as medium severity and maps it to CWE-200 (Information Exposure), with Cisco referencing advisory cisco-sa-20170215-cucm3 and fixed releases available for affected builds.

HIGH Cisco CVE published 2017-02-22

CVE-2017-3835

CVE-2017-3835 affects Cisco Identity Services Engine (ISE) sponsor portal and is described by Cisco and NVD as a SQL injection issue. An authenticated remote attacker could access notices owned by other users. NVD rates the issue 8.8 (HIGH) with a network-exploitable, low-complexity attack requiring low privileges and no user interaction.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3833

CVE-2017-3833 is a medium-severity cross-site scripting vulnerability in the web framework of Cisco Unified Communications Manager. Cisco and NVD describe it as allowing an unauthenticated, remote attacker to conduct an XSS attack against a user of the affected web interface. The supplied record lists one known affected release, 12.0(0.99999.2), and multiple fixed releases across 11.0, 11.5, 11.6, and 12.0 builds.

HIGH Cisco CVE published 2017-02-22

CVE-2017-3830

CVE-2017-3830 is a high-severity denial-of-service issue in Cisco Meeting Server (CMS). According to Cisco and NVD, an unauthenticated remote attacker could trigger a DoS condition through an internal API on affected appliances. Cisco lists CMS 2.1.0 as affected and 2.1.2 as the fixed release.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3829

CVE-2017-3829 is a cross-site scripting flaw in the web-based management interface of Cisco Unified Communications Manager Switches. Because the attack is remote and unauthenticated but requires user interaction, it is a medium-severity issue that should be patched and treated as an exposure risk for any environment where the management UI is reachable by admins.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3828

CVE-2017-3828 is a Cisco web-management cross-site scripting issue affecting Unified Communications Manager Switches. According to the official CVE/NVD record, an unauthenticated remote attacker could trigger XSS against a user of the web-based management interface. The NVD record classifies the flaw as CWE-79 and rates it CVSS 3.0 6.1 (Medium). Cisco listed affected releases 11.0(1.10000.10) and 11.5(1.1 [truncated]

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3827

CVE-2017-3827 describes a MIME scanner issue in Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA). On affected releases, an unauthenticated remote attacker could bypass configured user filters, reducing the effectiveness of attachment- and content-scanning policy enforcement. Cisco and NVD rate the issue as medium severity (CVSS 5.8).

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3821

CVE-2017-3821 is a reflected cross-site scripting flaw in the serviceability page of Cisco Unified Communications Manager. Cisco’s advisory is referenced by NVD, and the vulnerability is described as remotely reachable by an unauthenticated attacker. Because successful XSS can run in a user’s browser with the privileges of the viewing session, administrators should treat exposed management interfaces as s [truncated]

HIGH Cisco CVE published 2017-02-15

CVE-2017-3801

CVE-2017-3801 is a privilege-escalation issue in Cisco UCS Director’s web-based GUI. If Developer Menu is enabled, an authenticated local user with only an end-user profile can bypass intended role-based access control and add catalogs containing arbitrary workflow items, potentially triggering actions that affect other tenants.

HIGH Cisco CVE published 2017-02-09

CVE-2017-3813

CVE-2017-3813 affects Cisco AnyConnect Secure Mobility Client on Windows. A flaw in the Start Before Logon (SBL) module’s access controls could let a local attacker open Internet Explorer in the SYSTEM context, which could be used to run privileged commands. Cisco lists fixed releases 4.4.00243 and later, and 4.3.05017 and later.

HIGH Cisco CVE published 2017-02-09

CVE-2017-3807

CVE-2017-3807 is a high-severity heap overflow in Cisco ASA Clientless SSL VPN CIFS code caused by insufficient validation of user-supplied input. Cisco’s NVD record says an authenticated remote attacker can trigger the flaw with a crafted URL, potentially forcing a reload and, in some cases, code execution.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3824

CVE-2017-3824 is a denial-of-service vulnerability in Cisco cBR Series Converged Broadband Routers. According to Cisco and NVD, an unauthenticated remote attacker can abuse list header handling to trigger a device reload. The impact is service disruption rather than direct code execution, but the affected router is infrastructure-critical, so even a reload can be operationally significant.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3822

CVE-2017-3822 is a Cisco Firepower Threat Defense logging subsystem issue that can let an unauthenticated remote attacker add arbitrary entries to the audit log on affected Firepower Device Manager-enabled appliances. The vulnerability is rated medium severity and was addressed in Cisco Firepower Threat Defense Software 6.2.0.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3820

CVE-2017-3820 affects Cisco ASR 1000 Series Aggregation Services Routers running specific IOS XE releases and can let an authenticated remote attacker drive the device to high CPU usage, resulting in denial of service. The NVD record rates the issue CVSS 6.5 (Medium) and ties it to an availability impact with no confidentiality or integrity impact.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3818

CVE-2017-3818 is a medium-severity flaw in the MIME scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA). A remote unauthenticated attacker could bypass configured user filters by sending a malformed MIME header, potentially allowing unwanted email attachments to evade message or content filtering. Cisco states the issue affects releases prior to the first fixed release when attachm [truncated]

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3814

CVE-2017-3814 is a Cisco URL bypass issue that could let an unauthenticated remote attacker evade web-content blocking controls on affected Firepower software. NVD rates it CVSS 5.8 (Medium), with network reachability and no authentication required, so organizations that depend on Cisco URL filtering should treat it as a control-enforcement weakness rather than a code-execution event.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3812

CVE-2017-3812 is a Cisco Industrial Ethernet 2000 Series Switch vulnerability in Common Industrial Protocol (CIP) handling that can let an unauthenticated remote attacker trigger a denial of service condition by causing a system memory leak. The issue is documented by Cisco and NVD, with the affected firmware identified as 15.2(5.4.32i)E2 and the fixed release as 15.2(5.4.62i)E2. In the supplied record, t [truncated]

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3810

CVE-2017-3810 is a medium-severity Cisco Prime Service Catalog issue in the web framework that could let an authenticated, remote attacker perform a web URL redirect attack against a user who is already logged in to an affected system. Cisco’s advisory ties the issue to CWE-601 (Open Redirect). The affected release identified in the source corpus is 10.0_R2_tanggula, and the NVD CVSS v3.0 vector reflects [truncated]

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3809

CVE-2017-3809 affects Cisco Firepower Management Center (FMC) policy deployment in the 6.1.0 and 6.2.0 releases. According to the CVE record, an unauthenticated remote attacker could interfere with policy deployment so the rule base is not complete or accurate. Cisco lists fixed releases 6.1.0.1 and 6.2.0, and NVD classifies the issue as network-reachable with low attack complexity and integrity impact.

MEDIUM Cisco CVE published 2017-02-03

CVE-2017-3806

CVE-2017-3806 is a Cisco command-injection vulnerability in CLI command processing affecting Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance. According to the supplied records, an authenticated local attacker could inject arbitrary shell commands that the device executes. Cisco’s advisory and the NVD record both associate the issue with Firepower Threat Def [truncated]

CRITICAL Cisco CVE published 2017-02-01

CVE-2017-3792

CVE-2017-3792 is a critical, network-reachable flaw in Cisco TelePresence MCU Software that can be triggered by an unauthenticated remote attacker. Improper size validation during fragmented IPv4/IPv6 packet reassembly can overflow a buffer, creating a path to arbitrary code execution or a denial of service on affected MCU systems in Passthrough content mode.