cisco-sa-20180718-csp2100-injection
Cisco Cloud Services Platform 2100 Web Upload Function Code Injection Vulnerability
CVEs:CVE-2018-0394
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-220301 | affected | Cisco | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
Cisco Cloud Services Platform 2100 Web Upload Function Code Injection Vulnerability
CVEs:CVE-2018-0394
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-220301 | affected | Cisco | — | — |
Multiple Vulnerabilities in Cisco Finesse
CVEs:CVE-2018-0398CVE-2018-0399
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-193469 | affected | Cisco | — | — |
Cisco Policy Suite Cluster Manager Default Password Vulnerability
CVEs:CVE-2018-0375
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco Policy Suite Read-Only User Effect Change Vulnerability
CVEs:CVE-2018-0393
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco Policy Suite World-Readable Sensitive Data Vulnerability
CVEs:CVE-2018-0392
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco Policy Suite Policy Builder Database Unauthenticated Access Vulnerability
CVEs:CVE-2018-0374
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco Policy Suite OSGi Interface Unauthenticated Access Vulnerability
CVEs:CVE-2018-0377
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco Policy Suite Policy Builder Unauthenticated Access Vulnerability
CVEs:CVE-2018-0376
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-213864 | affected | Cisco | — | — |
Cisco SD-WAN Solution Local Buffer Overflow Vulnerability
CVEs:CVE-2018-0342
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Command Injection Vulnerability
CVEs:CVE-2018-0344
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Remote Code Execution Vulnerability
CVEs:CVE-2018-0343
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Zero Touch Provisioning Command Injection Vulnerability
CVEs:CVE-2018-0347
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution VPN Subsystem Command Injection Vulnerability
CVEs:CVE-2018-0350
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution CLI Command Injection Vulnerability
CVEs:CVE-2018-0348
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Command Injection Vulnerability
CVEs:CVE-2018-0351
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Configuration and Management Database Remote Code Execution Vulnerability
CVEs:CVE-2018-0345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Zero Touch Provisioning Denial of Service Vulnerability
CVEs:CVE-2018-0346
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Arbitrary File Overwrite Vulnerability
CVEs:CVE-2018-0349
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Multiple Vulnerabilities in Cisco Unified Contact Center Express
CVEs:CVE-2018-0400CVE-2018-0401CVE-2018-0402CVE-2018-0403
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-92631 | affected | Cisco | — | — |
Cisco Unified Communications Manager IM And Presence Service Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0396
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189784 | affected | Cisco | — | — |
Cisco Webex DOM-Based Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0390
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-241269 | affected | Cisco | — | — |
Cisco Webex Network Recording Players Denial of Service Vulnerabilities
CVEs:CVE-2018-0380
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-100455 | affected | Cisco | — | — |
| CVRFPID-96064 | affected | Cisco | — | — |
Cisco Webex Network Recording Players Remote Code Execution Vulnerabilities
CVEs:CVE-2018-0379
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-100455 | affected | Cisco | — | — |
| CVRFPID-96064 | affected | Cisco | — | — |
Cisco Webex Teams Remote Code Execution Vulnerability
CVEs:CVE-2018-0387
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-210403 | affected | Cisco | — | — |
Cisco Digital Network Architecture Center Credential Logging Information Disclosure Vulnerability
CVEs:CVE-2018-0368
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-233151 | affected | Cisco | — | — |
Cisco Firepower System Software Detection Engine Denial of Service Vulnerability
CVEs:CVE-2018-0370
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-212162 | affected | Cisco | — | — |
Cisco Firepower System Software SSL Denial of Service Vulnerability
CVEs:CVE-2018-0385
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-212162 | affected | Cisco | — | — |
Cisco FireSIGHT System Software File Policy Bypass Vulnerability
CVEs:CVE-2018-0383
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-205007 | affected | Cisco | — | — |
Cisco FireSIGHT System Software URL-Based Access Control Policy Bypass Vulnerability
CVEs:CVE-2018-0384
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-205007 | affected | Cisco | — | — |
Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware Web UI Command Injection Vulnerability
CVEs:CVE-2018-0341
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-235374 | affected | Cisco | — | — |
| CVRFPID-238623 | affected | Cisco | — | — |
| CVRFPID-238624 | affected | Cisco | — | — |
Cisco StarOS IPv4 Fragmentation Denial of Service Vulnerability
CVEs:CVE-2018-0369
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-193199 | affected | Cisco | — | — |
| CVRFPID-217771 | affected | Cisco | — | — |
Cisco Web Security Appliance Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0366
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.