Cisco Security Advisories · February 2019 — Cisco Security Advisories
31 advisories 31 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2019-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-20190227-rmi-cmd-ex

Cisco PSIRTExploitedHIGH2019-02-27

Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability

CVEs:CVE-2019-1663

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212336 affected Cisco
CVRFPID-212341 affected Cisco
CVRFPID-212498 affected Cisco
Upstream advisory

cisco-sa-20190227-wmda-cmdinj

Cisco PSIRTHIGH2019-02-27

Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools Update Service Command Injection Vulnerability

CVEs:CVE-2019-1674

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-97148 affected Cisco
CVRFPID-97151 affected Cisco
CVRFPID-97163 affected Cisco
CVRFPID-97166 affected Cisco
Upstream advisory

cisco-sa-20190220-cdp-lldp-dos

Cisco PSIRTHIGH2019-02-20

Cisco IP Phone 7800 and 8800 Series Cisco Discovery Protocol and Link Layer Discovery Protocol Denial of Service Vulnerability

CVEs:CVE-2019-1684

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205455 affected Cisco
CVRFPID-211541 affected Cisco
CVRFPID-238624 affected Cisco
Upstream advisory

cisco-sa-20190220-firpwr-dos

Cisco PSIRTHIGH2019-02-20

Cisco Firepower 9000 Series Firepower 2-Port 100G Double-Width Network Module Queue Wedge Denial of Service Vulnerability

CVEs:CVE-2019-1700

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-225888 affected Cisco
Upstream advisory

cisco-sa-20190220-ipphone-certs

Cisco PSIRTHIGH2019-02-20

Cisco SPA112, SPA525, and SPA5x5 Series IP Phones Certificate Validation Vulnerability

CVEs:CVE-2019-1683

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-117236 affected Cisco
CVRFPID-255654 affected Cisco
Upstream advisory

cisco-sa-20190220-ncs

Cisco PSIRTHIGH2019-02-20

Cisco Network Convergence System 1000 Series TFTP Directory Traversal Vulnerability

CVEs:CVE-2019-1681

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-255125 affected Cisco
Upstream advisory

cisco-sa-20190206-cuic-xss

Cisco PSIRTHIGH2019-02-06

Cisco Unified Intelligence Center Software Cross-Site Scripting Vulnerability

CVEs:CVE-2019-1670

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-198393 affected Cisco
CVRFPID-92631 affected Cisco
Upstream advisory

cisco-sa-20190206-rest-api-ssrf

Cisco PSIRTHIGH2019-02-06

Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server REST API Server-Side Request Forgery Vulnerability

CVEs:CVE-2019-1679

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-202683 affected Cisco
CVRFPID-203755 affected Cisco
CVRFPID-209614 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.