cisco-sa-20180828-dcnm-traversal
Cisco Data Center Network Manager Path Traversal Vulnerability
CVEs:CVE-2018-0464
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-233075 | affected | Cisco | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.
Cisco Data Center Network Manager Path Traversal Vulnerability
CVEs:CVE-2018-0464
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-233075 | affected | Cisco | — | — |
Linux Kernel IP Fragment Reassembly Denial of Service Vulnerability Affecting Cisco Products: August 2018
CVEs:CVE-2018-5391
Linux and FreeBSD Kernels TCP Reassembly Denial of Service Vulnerabilities Affecting Cisco Products: August 2018
Apache Struts Remote Code Execution Vulnerability Affecting Cisco Products: August 2018
CVEs:CVE-2018-11776
Cisco ASR 9000 Series Aggregation Services Routers Precision Time Protocol Denial of Service Vulnerability
CVEs:CVE-2018-0418
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-202356 | affected | Cisco | — | — |
Cisco Small Business 100 Series and 300 Series Wireless Access Points Denial of Service Vulnerability
CVEs:CVE-2018-0415
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-230666 | affected | Cisco | — | — |
| CVRFPID-230676 | affected | Cisco | — | — |
Cisco Unified Communications Domain Manager Reflected Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0386
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-188989 | affected | Cisco | — | — |
Cisco Digital Network Architecture Center Command Injection Vulnerability
CVEs:CVE-2018-0427
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-233151 | affected | Cisco | — | — |
Cisco Email Security Appliance EXE File Scanning Bypass Vulnerability
CVEs:CVE-2018-0419
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189790 | affected | Cisco | — | — |
Cisco Registered Envelope Service Stored Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0367
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-225817 | affected | Cisco | — | — |
Cisco Small Business 100 Series and 300 Series Wireless Access Points Encryption Algorithm Downgrade Vulnerability
CVEs:CVE-2018-0412
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-230666 | affected | Cisco | — | — |
| CVRFPID-230676 | affected | Cisco | — | — |
Cisco Unified Communications Manager IM & Presence Service Denial of Service Vulnerability
CVEs:CVE-2018-0409
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189784 | affected | Cisco | — | — |
| CVRFPID-209614 | affected | Cisco | — | — |
Cisco Web Security Appliance Web Proxy Memory Exhaustion Denial of Service Vulnerability
CVEs:CVE-2018-0410
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
Cisco Web Security Appliance Privilege Escalation Vulnerability
CVEs:CVE-2018-0428
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
CPU Side-Channel Information Disclosure Vulnerabilities: August 2018
Cisco IOS and IOS XE Software Internet Key Exchange Version 1 RSA-Encrypted Nonces Vulnerability
CVEs:CVE-2018-0131
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-2097 | affected | Cisco | — | — |
| CVRFPID-93036 | affected | Cisco | — | — |
Cisco AMP for Endpoints Mac Connector Software Denial of Service Vulnerability
CVEs:CVE-2018-0397
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-221075 | affected | Cisco | — | — |
Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
CVEs:CVE-2018-0413
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-111903 | affected | Cisco | — | — |
Cisco Prime Collaboration Provisioning Unauthorized Password Change Denial of Service Vulnerability
CVEs:CVE-2018-0391
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-209583 | affected | Cisco | — | — |
Cisco Small Business 300 Series Managed Switches Persistent Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0407
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-187435 | affected | Cisco | — | — |
Cisco Small Business 300 Series Managed Switches Authenticated Reflected Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0408
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-187435 | affected | Cisco | — | — |
Cisco Unified Communications Manager Reflected Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0411
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-88444 | affected | Cisco | — | — |
Cisco Web Security Appliance Reflected and Document Object Model-Based Cross-Site Scripting Vulnerability
CVEs:CVE-2018-0406
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.