Cisco Security Advisories · February 2018 — Cisco Security Advisories
32 advisories 32 CVEs 2 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2018-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-20180221-cvp

Cisco PSIRT2018-02-21

Cisco Unified Customer Voice Portal Interactive Voice Response Connection Denial of Service Vulnerability

CVEs:CVE-2018-0139

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-8027 affected Cisco
Upstream advisory

cisco-sa-20180221-esc

Cisco PSIRTHIGH2018-02-21

Cisco Elastic Services Controller Service Portal Authentication Bypass Vulnerability

CVEs:CVE-2018-0121

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-227689 affected Cisco
Upstream advisory

cisco-sa-20180221-esc1

Cisco PSIRTHIGH2018-02-21

Cisco Elastic Services Controller Service Portal Unauthorized Access Vulnerability

CVEs:CVE-2018-0130

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-227689 affected Cisco
Upstream advisory

cisco-sa-20180221-jcf

Cisco PSIRT2018-02-21

Cisco Jabber Client Framework for Windows and Mac Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0199

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-192127 affected Cisco
CVRFPID-210554 affected Cisco
Upstream advisory

cisco-sa-20180221-jcf1

Cisco PSIRT2018-02-21

Cisco Jabber Client Framework for Windows and Mac Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0201

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-192127 affected Cisco
CVRFPID-210554 affected Cisco
Upstream advisory

cisco-sa-20180221-pcpt

Cisco PSIRT2018-02-21

Cisco Prime Collaboration Provisioning Tool Web Portal Repeated Bad Login Attempts Denial of Service Vulnerability

CVEs:CVE-2018-0204

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20180221-pcpt1

Cisco PSIRT2018-02-21

Cisco Prime Collaboration Provisioning Tool User Provisioning Tab Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0205

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20180221-ucm

Cisco PSIRTHIGH2018-02-21

Multiple Cisco Unified Communications Products Reflected Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0206

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-4844 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-20180221-ucsd

Cisco PSIRT2018-02-21

Cisco UCS Director and Cisco Integrated Management Controller Supervisor Cross-Site Request Forgery Vulnerability

CVEs:CVE-2018-0148

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-197112 affected Cisco
CVRFPID-209194 affected Cisco
Upstream advisory

cisco-sa-20180207-asr

Cisco PSIRT2018-02-07

Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability

CVEs:CVE-2018-0122

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-193199 affected Cisco
Upstream advisory

cisco-sa-20180207-esacsm

Cisco PSIRT2018-02-07

Cisco Email Security Appliance and Cisco Content Security Management Appliance Spam Quarantine Vulnerability

CVEs:CVE-2018-0140

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189790 affected Cisco
CVRFPID-189791 affected Cisco
Upstream advisory

cisco-sa-20180207-iosxr

Cisco PSIRT2018-02-07

Cisco IOS XR Software Routing and Forwarding Inconsistency Denial of Service Vulnerability

CVEs:CVE-2018-0132

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-5834 affected Cisco
Upstream advisory

cisco-sa-20180207-rv13x

Cisco PSIRTExploitedHIGH2018-02-07

Cisco RV132W and RV134W Remote Code Execution and Denial of Service Vulnerability

CVEs:CVE-2018-0125

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
Upstream advisory

cisco-sa-20180207-rv13x_2

Cisco PSIRTExploited2018-02-07

Cisco RV132W and RV134W Wireless VPN Routers Unauthenticated Information Disclosure Vulnerability

CVEs:CVE-2018-0127

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-232399 affected Cisco
CVRFPID-232400 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.