These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-3791 is a critical authentication bypass in Cisco Prime Home’s web-based GUI. A processing error in role-based access control (RBAC) for URLs can let an unauthenticated remote attacker send HTTP API commands and perform actions with administrator privileges. Cisco reported that software updates address the issue and that no workaround is available.
CVE-2017-3790 is an unauthenticated, remote denial-of-service vulnerability in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software. According to the vendor and NVD summary, the issue is in the received packet parser and stems from insufficient size validation of user-supplied data. A crafted H.224 payload in RTP packets during an H.323 call can trigger a buffer overflo [truncated]
CVE-2016-9225 describes a denial-of-service issue in the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module's data plane IP fragment handler. An unauthenticated remote attacker can send crafted fragmented IP traffic that exhausts free packet buffers in shared memory, leaving the CX module unable to process further traffic. Cisco and NVD characterize this as a high-severity availabili [truncated]
CVE-2017-3823 is a high-severity remote code execution issue in several Cisco WebEx browser extensions and plugins on Microsoft Windows. A successful attack requires user interaction, but an unauthenticated remote attacker could trigger code execution with the privileges of the affected browser by luring the user to an attacker-controlled page or link.
CVE-2017-3805 is an unauthenticated, remote information disclosure issue in the web-based management interface of certain Cisco IOS and Cisco IOx deployments. Cisco identifies affected platforms as IR829, IR809, IE4K, and CGR1K, with NVD scoring the issue 5.3/Medium and classifying it as CWE-200.
CVE-2017-3804 is a medium-severity Cisco Nexus NX-OS vulnerability in IS-IS packet processing that can let an unauthenticated, adjacent attacker trigger a reload of an affected switch. The issue is described as a crash in the FabricPath domain when processing a crafted link-state packet. For network operators, the practical risk is an availability impact on affected Nexus 5000, 6000, and 7000 Series switc [truncated]
CVE-2017-3803 is a Cisco IOS Software issue affecting Cisco 2960X and 3750X switches. According to the NVD record and Cisco advisory references, an unauthenticated adjacent attacker could trigger a memory leak in the software forwarding queue that may eventually cause a partial denial of service condition. The published CVSS v3.0 vector reflects adjacent attack conditions and availability impact only.
CVE-2017-3802 is a cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager's web interface. According to the CVE/NVD record, an unauthenticated remote attacker could trigger the issue against a user of the affected web interface. Cisco lists affected release 12.0(0.99000.9) and multiple fixed releases, and NVD scores the issue as CVSS 3.0 6.1 (Medium).
CVE-2017-3800 is a Cisco AsyncOS issue in the content scanning engine for Cisco Email Security Appliances (ESA). If the appliance is configured to apply message or content filters to incoming email attachments, a remote unauthenticated attacker may be able to bypass those filters. Cisco and NVD list fixed releases and affected versions for ESA deployments on both virtual and hardware platforms.
CVE-2017-3799 is a Cisco WebEx Meeting Center issue involving a URL parameter that can enable site redirection. Cisco lists T28.1 as a known affected release. From a defender’s perspective, redirect flaws can be abused to send users to attacker-controlled destinations, increasing phishing and trust-abuse risk.
CVE-2017-3798 is a medium-severity cross-site scripting (XSS) filter bypass in the web-based management interface of Cisco Unified Communications Manager. Cisco and NVD describe it as allowing an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. The NVD record classifies it as CWE-79 and gives it CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
CVE-2017-3797 is an information disclosure issue in Cisco WebEx Meetings Server. An unauthenticated remote attacker could view the fully qualified domain name of the Cisco WebEx administration server. NVD rates the issue CVSS 3.0 5.3/Medium, with confidentiality impact limited and no integrity or availability impact recorded.
CVE-2017-3796 affects Cisco WebEx Meetings Server 2.6 and allows an authenticated, remote attacker to execute predetermined shell commands on other hosts. The vulnerability is rated HIGH by NVD and maps to CWE-78 (OS Command Injection). Because exploitation requires authentication but can affect host integrity and availability, it deserves prompt review in any environment that still runs the affected release.
CVE-2017-3795 affects Cisco WebEx Meetings Server 2.6. Cisco describes it as allowing an authenticated, remote attacker to perform arbitrary password changes against any non-administrative user. NVD assigns CVSS 3.0 5.4 (MEDIUM) and maps the issue to CWE-287. Cisco lists 2.7.1.12 as the known fixed release.
CVE-2017-3794 is a cross-site request forgery (CSRF) issue in Cisco WebEx Meetings Server. A remote attacker can try to induce an administrative user’s browser to send unintended requests, which can affect server state through the admin session. Cisco lists WebEx Meetings Server 2.6 as affected and 2.7.1.12 as the fixed release; NVD maps the weakness to CWE-352.
CVE-2016-9222 is a medium-severity cross-site scripting issue in the web-based management interface of Cisco NetFlow Generation Appliance. An unauthenticated remote attacker could trigger XSS against a user of the interface on affected release 1.0(2). Cisco and NVD both list this as a CWE-79 issue, and the NVD vector requires user interaction.
CVE-2016-9221 is a Cisco Mobility Express wireless denial-of-service issue that can cause authentication to fail on affected 2800 and 3800 Series access points. The supplied vendor and NVD data indicate the issue is reachable by an unauthenticated adjacent attacker and affects specific local-mode deployments using 40 MHz operation. Cisco lists fixed releases and recommends upgrading to a non-vulnerable version.
CVE-2016-9220 is a denial-of-service issue in 802.11 ingress packet processing on Cisco Mobility Express 2800 and 3800 Access Points. An unauthenticated attacker on an adjacent network can cause the connection table to fill with invalid connections, preventing the device from processing new incoming requests. Cisco identified affected release 8.2(130.0) and published fixed releases in several later trains.
CVE-2016-9218 is a cross-site request forgery (CSRF) vulnerability in Cisco Hybrid Meeting Server. According to the CVE record, an unauthenticated remote attacker could conduct a CSRF attack against a user of the web interface. The NVD entry maps this to CWE-352 and lists Cisco Hybrid Meeting Server 1.0_base as affected. Because the attack requires user interaction but can impact confidentiality, integrit [truncated]
CVE-2016-9216 describes an IKE packet parsing denial-of-service issue in Cisco ASR 5000 Software. A remote, unauthenticated attacker could cause the ipsecmgr process to reload, which can disrupt IPsec-related service handling. The CVE was published on 2017-01-26 and is scored CVSS 3.0 5.3 (Medium).