Cisco Security Advisories · August 2018 — Cisco Security Advisories
23 advisories 26 CVEs 2 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2018-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-20180815-csb-wap-dos

Cisco PSIRT2018-08-15

Cisco Small Business 100 Series and 300 Series Wireless Access Points Denial of Service Vulnerability

CVEs:CVE-2018-0415

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-230666 affected Cisco
CVRFPID-230676 affected Cisco
Upstream advisory

cisco-sa-20180815-sb-wap-encrypt

Cisco PSIRT2018-08-15

Cisco Small Business 100 Series and 300 Series Wireless Access Points Encryption Algorithm Downgrade Vulnerability

CVEs:CVE-2018-0412

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-230666 affected Cisco
CVRFPID-230676 affected Cisco
Upstream advisory

cisco-sa-20180815-ucmimps-dos

Cisco PSIRT2018-08-15

Cisco Unified Communications Manager IM & Presence Service Denial of Service Vulnerability

CVEs:CVE-2018-0409

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-209614 affected Cisco
Upstream advisory

cisco-sa-20180813-rsa-nonce

Cisco PSIRT2018-08-13

Cisco IOS and IOS XE Software Internet Key Exchange Version 1 RSA-Encrypted Nonces Vulnerability

CVEs:CVE-2018-0131

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-2097 affected Cisco
CVRFPID-93036 affected Cisco
Upstream advisory

cisco-sa-20180801-pcp-dos

Cisco PSIRT2018-08-01

Cisco Prime Collaboration Provisioning Unauthorized Password Change Denial of Service Vulnerability

CVEs:CVE-2018-0391

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-209583 affected Cisco
Upstream advisory

cisco-sa-20180801-sb-rxss

Cisco PSIRT2018-08-01

Cisco Small Business 300 Series Managed Switches Authenticated Reflected Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0408

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-187435 affected Cisco
Upstream advisory

cisco-sa-20180801-wsa-xss

Cisco PSIRT2018-08-01

Cisco Web Security Appliance Reflected and Document Object Model-Based Cross-Site Scripting Vulnerability

CVEs:CVE-2018-0406

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189789 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.