A buffer overflow in the web UI of several Cisco SIP desk and video phones lets a remote attacker crash the device with a single crafted HTTP request, provided Web Access is turned on.
Posts tagged: Cisco
Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability
An authenticated admin on Cisco Unified Communications Manager’s web interface can plant script that runs in another admin’s browser session, with no workaround available other than upgrading.
Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities
Two stored XSS flaws in Cisco Cyber Vision Center’s Sensor Explorer and Reports pages let an authenticated user plant scripts that run in other admins’ browsers, with no workaround and a fix-only path.
Cisco IOS XE Software Web Authentication Reflected Cross-Site Scripting Vulnerability
A reflected XSS bug in Cisco IOS XE’s web authentication portal lets an attacker steal a user’s session cookie if they click a crafted link, but only on devices running HTTP/HTTPS with Web Authentication enabled.
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability
Anyone holding valid VPN credentials can send crafted HTTP requests to the ASA/FTD VPN web server and gain root code execution, with no workaround to fall back on.
Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
A flaw in the web services shared by Cisco ASA, FTD, IOS, IOS XE and IOS XR lets an attacker send crafted HTTP requests to run code as root, with ASA/FTD reachable without any login.
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
An unauthenticated attacker can send crafted HTTP requests to the VPN web server on Cisco ASA and FTD devices and reach restricted URL endpoints that should require login.
Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability
An unauthenticated attacker within radio range of a Cisco access point can forge 802.11 action frames to corrupt Device Analytics data for other clients on the same wireless controller.
Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability
Wireless clients can send crafted IPv6 router advertisements to trick Cisco access points using CAPWAP over IPv6 into flipping their gateway, causing intermittent packet loss for connected devices.
Cisco IOS XE Software for Catalyst 9000 Series Switches Denial of Service Vulnerability
A crafted Ethernet frame sent to a trunk, TrustSec or MACsec-enabled port on a Catalyst 9000 switch can jam the egress queue and stop all outbound traffic on that port, with no workaround and a reload the only fix.