A stored input-validation flaw in Cisco Unified CM IM&P’s admin web interface lets an attacker run script in a user’s browser session if that user clicks a crafted link.
Posts tagged: Cisco
Cisco Webex Meetings URL Redirection Vulnerability
Cisco Webex Meetings failed to properly validate URLs in meeting-join links, letting an unauthenticated attacker craft links that send users to an untrusted site instead of the genuine Webex page.
Cisco Webex Meetings Cross-Site Scripting Vulnerability
An authenticated user tricked into clicking a crafted link could trigger script execution in another Webex Meetings user’s session, but Cisco has already fixed this server-side with nothing for customers to patch.
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
Cisco’s Unified Communications Manager admin web interface lacks proper CSRF protection, letting an attacker trick a logged-in administrator into unknowingly executing actions on the call-management system.
Cisco Nexus Dashboard Path Traversal Vulnerability
An admin-only backup restore flaw in Cisco Nexus Dashboard lets someone with valid Administrator credentials plant a crafted backup file that escalates them to root on the underlying host.
Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities
Missing authorisation checks on some Nexus Dashboard and NDFC REST API endpoints let a low-privileged, authenticated user read proxy and NTP settings and tamper with image files, with no workaround available.
Cisco NX-OS Software Command Injection Vulnerability
An authenticated CLI user on Cisco NX-OS switches and fabric interconnects can inject crafted command arguments to read and write OS files, limited to whatever permissions their non-root account already has.
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
Cisco NX-OS logs can capture stored credentials in plain text, letting anyone with local file-system access on Nexus or UCS gear read them straight out of the logs.
Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability
An authenticated low-privileged attacker who can reach NX-API, NETCONF, RESTCONF, gRPC or telemetry on a Nexus 3000/9000 switch can crash the PIM6 process, disrupting multicast routing until it restarts.
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Stored Cross-Site Scripting Vulnerability
A stored XSS flaw in Cisco IMC’s virtual keyboard/video monitor interface lets a low-privileged, already-authenticated user plant script that runs in another vKVM user’s session, and the same client ships inside a long list of UCS-based appliances.