Cisco Security Advisories · May 2018 — Cisco Security Advisories
36 advisories 37 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2018-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

Advisories

cisco-sa-20180516-cucm-cup-xss

Cisco PSIRT2018-05-16

Cisco Unified Communications Manager and Cisco Unified Presence Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0328

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-7333 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-20180516-fnd

Cisco PSIRT2018-05-16

Cisco IoT Field Network Director Cross-Site Request Forgery Vulnerability

CVEs:CVE-2018-0270

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-227605 affected Cisco
CVRFPID-237479 affected Cisco
CVRFPID-237480 affected Cisco
Upstream advisory

cisco-sa-20180516-ip-phone-dos

Cisco PSIRT2018-05-16

Cisco IP Phone 7800 Series and 8800 Series and Cisco Wireless IP Phone 8821 Denial of Service Vulnerability

CVEs:CVE-2018-0325

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205455 affected Cisco
CVRFPID-211541 affected Cisco
Upstream advisory

cisco-sa-20180516-telepres-xfs

Cisco PSIRT2018-05-16

Cisco TelePresence IX5000 Series and TelePresence TX9000 Series Cross-Frame Scripting Vulnerability

CVEs:CVE-2018-0326

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190445 affected Cisco
CVRFPID-210082 affected Cisco
Upstream advisory

cisco-sa-20180502-aironet-auth

Cisco PSIRT2018-05-02

Cisco Wireless LAN Controller and Aironet Access Points IOS WebAuth Client Authentication Bypass Vulnerability

CVEs:CVE-2018-0247

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
CVRFPID-7368 affected Cisco
Upstream advisory

cisco-sa-20180502-ap-acl

Cisco PSIRT2018-05-02

Cisco Aironet Access Points Central Web Authentication FlexConnect Client ACL Bypass Vulnerability

CVEs:CVE-2018-0250

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
Upstream advisory

cisco-sa-20180502-ap-ptp

Cisco PSIRT2018-05-02

Cisco Aironet 1810, 1830, and 1850 Series Access Points Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVEs:CVE-2018-0234

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-230258 affected Cisco
Upstream advisory

cisco-sa-20180502-prime-upload

Cisco PSIRT2018-05-02

Cisco Prime File Upload Servlet Path Traversal and Remote Code Execution Vulnerability

CVEs:CVE-2018-0258

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-185359 affected Cisco
CVRFPID-190324 affected Cisco
Upstream advisory

cisco-sa-20180502-war

Cisco PSIRT2018-05-02

Cisco WebEx Advanced Recording Format Remote Code Execution Vulnerability

CVEs:CVE-2018-0264

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-100455 affected Cisco
CVRFPID-190702 affected Cisco
CVRFPID-228295 affected Cisco
Upstream advisory

cisco-sa-20180502-webex-id

Cisco PSIRT2018-05-02

Cisco WebEx Recording Format Player Information Disclosure Vulnerability

CVEs:CVE-2018-0288

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-228295 affected Cisco
CVRFPID-96064 affected Cisco
Upstream advisory

cisco-sa-20180502-webex-rce

Cisco PSIRT2018-05-02

Cisco WebEx Advanced Recording Format Player Remote Code Execution Vulnerability

CVEs:CVE-2018-0287

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-100455 affected Cisco
CVRFPID-190702 affected Cisco
CVRFPID-228295 affected Cisco
Upstream advisory

cisco-sa-20180502-wlc-ip

Cisco PSIRT2018-05-02

Cisco Wireless LAN Controller IP Fragment Reassembly Denial of Service Vulnerability

CVEs:CVE-2018-0252

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-230842 affected Cisco
CVRFPID-230843 affected Cisco
CVRFPID-234402 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.