PatchSiren

Cisco CVE debriefs · Page 11

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Cisco CVE published 2017-02-01

CVE-2017-3791

CVE-2017-3791 is a critical authentication bypass in Cisco Prime Home’s web-based GUI. A processing error in role-based access control (RBAC) for URLs can let an unauthenticated remote attacker send HTTP API commands and perform actions with administrator privileges. Cisco reported that software updates address the issue and that no workaround is available.

HIGH Cisco CVE published 2017-02-01

CVE-2017-3790

CVE-2017-3790 is an unauthenticated, remote denial-of-service vulnerability in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software. According to the vendor and NVD summary, the issue is in the received packet parser and stems from insufficient size validation of user-supplied data. A crafted H.224 payload in RTP packets during an H.323 call can trigger a buffer overflo [truncated]

HIGH Cisco CVE published 2017-02-01

CVE-2016-9225

CVE-2016-9225 describes a denial-of-service issue in the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module's data plane IP fragment handler. An unauthenticated remote attacker can send crafted fragmented IP traffic that exhausts free packet buffers in shared memory, leaving the CX module unable to process further traffic. Cisco and NVD characterize this as a high-severity availabili [truncated]

HIGH Cisco CVE published 2017-02-01

CVE-2017-3823

CVE-2017-3823 is a high-severity remote code execution issue in several Cisco WebEx browser extensions and plugins on Microsoft Windows. A successful attack requires user interaction, but an unauthenticated remote attacker could trigger code execution with the privileges of the affected browser by luring the user to an attacker-controlled page or link.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3805

CVE-2017-3805 is an unauthenticated, remote information disclosure issue in the web-based management interface of certain Cisco IOS and Cisco IOx deployments. Cisco identifies affected platforms as IR829, IR809, IE4K, and CGR1K, with NVD scoring the issue 5.3/Medium and classifying it as CWE-200.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3804

CVE-2017-3804 is a medium-severity Cisco Nexus NX-OS vulnerability in IS-IS packet processing that can let an unauthenticated, adjacent attacker trigger a reload of an affected switch. The issue is described as a crash in the FabricPath domain when processing a crafted link-state packet. For network operators, the practical risk is an availability impact on affected Nexus 5000, 6000, and 7000 Series switc [truncated]

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3803

CVE-2017-3803 is a Cisco IOS Software issue affecting Cisco 2960X and 3750X switches. According to the NVD record and Cisco advisory references, an unauthenticated adjacent attacker could trigger a memory leak in the software forwarding queue that may eventually cause a partial denial of service condition. The published CVSS v3.0 vector reflects adjacent attack conditions and availability impact only.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3802

CVE-2017-3802 is a cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager's web interface. According to the CVE/NVD record, an unauthenticated remote attacker could trigger the issue against a user of the affected web interface. Cisco lists affected release 12.0(0.99000.9) and multiple fixed releases, and NVD scores the issue as CVSS 3.0 6.1 (Medium).

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3800

CVE-2017-3800 is a Cisco AsyncOS issue in the content scanning engine for Cisco Email Security Appliances (ESA). If the appliance is configured to apply message or content filters to incoming email attachments, a remote unauthenticated attacker may be able to bypass those filters. Cisco and NVD list fixed releases and affected versions for ESA deployments on both virtual and hardware platforms.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3799

CVE-2017-3799 is a Cisco WebEx Meeting Center issue involving a URL parameter that can enable site redirection. Cisco lists T28.1 as a known affected release. From a defender’s perspective, redirect flaws can be abused to send users to attacker-controlled destinations, increasing phishing and trust-abuse risk.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3798

CVE-2017-3798 is a medium-severity cross-site scripting (XSS) filter bypass in the web-based management interface of Cisco Unified Communications Manager. Cisco and NVD describe it as allowing an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. The NVD record classifies it as CWE-79 and gives it CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3797

CVE-2017-3797 is an information disclosure issue in Cisco WebEx Meetings Server. An unauthenticated remote attacker could view the fully qualified domain name of the Cisco WebEx administration server. NVD rates the issue CVSS 3.0 5.3/Medium, with confidentiality impact limited and no integrity or availability impact recorded.

HIGH Cisco CVE published 2017-01-26

CVE-2017-3796

CVE-2017-3796 affects Cisco WebEx Meetings Server 2.6 and allows an authenticated, remote attacker to execute predetermined shell commands on other hosts. The vulnerability is rated HIGH by NVD and maps to CWE-78 (OS Command Injection). Because exploitation requires authentication but can affect host integrity and availability, it deserves prompt review in any environment that still runs the affected release.

MEDIUM Cisco CVE published 2017-01-26

CVE-2017-3795

CVE-2017-3795 affects Cisco WebEx Meetings Server 2.6. Cisco describes it as allowing an authenticated, remote attacker to perform arbitrary password changes against any non-administrative user. NVD assigns CVSS 3.0 5.4 (MEDIUM) and maps the issue to CWE-287. Cisco lists 2.7.1.12 as the known fixed release.

HIGH Cisco CVE published 2017-01-26

CVE-2017-3794

CVE-2017-3794 is a cross-site request forgery (CSRF) issue in Cisco WebEx Meetings Server. A remote attacker can try to induce an administrative user’s browser to send unintended requests, which can affect server state through the admin session. Cisco lists WebEx Meetings Server 2.6 as affected and 2.7.1.12 as the fixed release; NVD maps the weakness to CWE-352.

MEDIUM Cisco CVE published 2017-01-26

CVE-2016-9222

CVE-2016-9222 is a medium-severity cross-site scripting issue in the web-based management interface of Cisco NetFlow Generation Appliance. An unauthenticated remote attacker could trigger XSS against a user of the interface on affected release 1.0(2). Cisco and NVD both list this as a CWE-79 issue, and the NVD vector requires user interaction.

MEDIUM Cisco CVE published 2017-01-26

CVE-2016-9221

CVE-2016-9221 is a Cisco Mobility Express wireless denial-of-service issue that can cause authentication to fail on affected 2800 and 3800 Series access points. The supplied vendor and NVD data indicate the issue is reachable by an unauthenticated adjacent attacker and affects specific local-mode deployments using 40 MHz operation. Cisco lists fixed releases and recommends upgrading to a non-vulnerable version.

MEDIUM Cisco CVE published 2017-01-26

CVE-2016-9220

CVE-2016-9220 is a denial-of-service issue in 802.11 ingress packet processing on Cisco Mobility Express 2800 and 3800 Access Points. An unauthenticated attacker on an adjacent network can cause the connection table to fill with invalid connections, preventing the device from processing new incoming requests. Cisco identified affected release 8.2(130.0) and published fixed releases in several later trains.

HIGH Cisco CVE published 2017-01-26

CVE-2016-9218

CVE-2016-9218 is a cross-site request forgery (CSRF) vulnerability in Cisco Hybrid Meeting Server. According to the CVE record, an unauthenticated remote attacker could conduct a CSRF attack against a user of the web interface. The NVD entry maps this to CWE-352 and lists Cisco Hybrid Meeting Server 1.0_base as affected. Because the attack requires user interaction but can impact confidentiality, integrit [truncated]

MEDIUM Cisco CVE published 2017-01-26

CVE-2016-9216

CVE-2016-9216 describes an IKE packet parsing denial-of-service issue in Cisco ASR 5000 Software. A remote, unauthenticated attacker could cause the ipsecmgr process to reload, which can disrupt IPsec-related service handling. The CVE was published on 2017-01-26 and is scored CVSS 3.0 5.3 (Medium).