A stored input-validation flaw in Cisco Catalyst Center’s web management interface lets an attacker run script in an operator’s browser via a crafted link, exposing session data or tokens.
Posts tagged: Cisco
Cisco Catalyst Center Privilege Escalation Vulnerability
A broken access control check in Cisco Catalyst Center lets a logged-in read-only user change policy configurations that should be locked to Administrator accounts.
Cisco Catalyst Center Virtual Appliance HTTP Open Redirect Vulnerability
Cisco Catalyst Center Virtual Appliance on VMware ESXi can be tricked into redirecting management-interface users to attacker-controlled pages via a tampered HTTP request, with no fix short of upgrading.
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Two unrelated bugs in Cisco Unified CCX’s Java RMI process and CCX Editor let an unauthenticated attacker upload files, bypass authentication, and run commands as root or as an internal user, with no workaround available.
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Authenticated users of Cisco ISE’s web management interface could trigger reflected XSS or pull sensitive data due to weak input validation, with fixes only via patched releases and no interim workaround.
Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco …
Multiple Cisco Contact Center Products Vulnerabilities
Authenticated users of Cisco’s Contact Centre platforms can exploit several bugs to read sensitive data, upload and run files, and escalate to root, with no workaround until patched.
Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco BroadWorks CommPilot lets an already-authenticated admin plant script that runs in another logged-in admin’s browser, with no workaround available beyond patching.
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
On Cisco TelePresence CE and RoomOS devices with SIP media logging switched on, audit logs store credentials unencrypted, letting an admin-level user harvest access they shouldn’t have.
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
Flaws in the Snort 3 MIME decoder let a remote attacker with no credentials crash the detection engine or pull sensitive data from traffic passing through Firepower and ISA appliances, with no workaround to fall back on.