<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T14:02:12.767678+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-00649</id>
    <title>bdu:2018-00649</title>
    <updated>2026-10-07T14:02:12.773076+00:00</updated>
    <content>bdu:2018-00649</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-00649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-156</id>
    <title>certfr-2018-avi-156 — De multiples vulnérabilités ont été découvertes dans les produits Cisco.
Certaines d'entre elles permettent à un attaqu…</title>
    <updated>2026-10-07T14:02:12.773110+00:00</updated>
    <content>certfr-2018-avi-156</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-20180328-xepriv</id>
    <title>cisco-sa-20180328-xepriv — Cisco IOS XE Software Web UI Remote Access Privilege Escalation Vulnerability</title>
    <updated>2026-10-07T14:02:12.773130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device.

The vulnerability exists because the affected software does not reset the privilege level for each web UI session. An attacker who has valid credentials for an affected device could exploit this vulnerability by remotely accessing a VTY line to the device. A successful exploit could allow the attacker to access an affected device with the privileges of the user who previously logged in to the web UI.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xepriv ["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xepriv"]
This advisory is part of the March 28, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 20 Cisco Security Advisories that describe 22 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-66682"].</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-20180328-xepriv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-07305</id>
    <title>cnvd-2018-07305</title>
    <updated>2026-10-07T14:02:12.773167+00:00</updated>
    <content>cnvd-2018-07305</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-07305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-205403</id>
    <title>EUVD-2026-205403</title>
    <updated>2026-10-07T14:02:12.773181+00:00</updated>
    <content>EUVD-2026-205403</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-205403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-0152</id>
    <title>fkie_cve-2018-0152</title>
    <updated>2026-10-07T14:02:12.773192+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does not reset the privilege level for each web UI session. An attacker who has valid credentials for an affected device could exploit this vulnerability by remotely accessing a VTY line to the device. A successful exploit could allow the attacker to access an affected device with the privileges of the user who previously logged in to the web UI. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled and authentication, authorization, and accounting (AAA) authorization is not configured for EXEC sessions. The default state of the HTTP Server feature is version-dependent. This vulnerability was introduced in Cisco IOS XE Software Release 16.1.1. Cisco Bug IDs: CSCvf71769.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-0152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4jvx-6g9p-mgxw</id>
    <title>GHSA-4jvx-6g9p-mgxw</title>
    <updated>2026-10-07T14:02:12.773217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability exists because the affected software does not reset the privilege level for each web UI session. An attacker who has valid credentials for an affected device could exploit this vulnerability by remotely accessing a VTY line to the device. A successful exploit could allow the attacker to access an affected device with the privileges of the user who previously logged in to the web UI. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled and authentication, authorization, and accounting (AAA) authorization is not configured for EXEC sessions. The default state of the HTTP Server feature is version-dependent. This vulnerability was introduced in Cisco IOS XE Software Release 16.1.1. Cisco Bug IDs: CSCvf71769.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4jvx-6g9p-mgxw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-0152</id>
    <title>gsd-2018-0152</title>
    <updated>2026-10-07T14:02:12.773236+00:00</updated>
    <content>gsd-2018-0152</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-0152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1871</id>
    <title>WID-SEC-W-2025-1871 — Cisco IOS: Mehrere Schwachstellen</title>
    <updated>2026-10-07T14:02:12.773246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco IOS und Cisco IOS XE ausnutzen, um Daten zu manipulieren, vertrauliche Daten einzusehen, einen Denial of Service Angriff durchzuführen, seine Privilegien zu erweitern, Cross-Site Scripting Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen oder beliebigen Code mit administrativen Privilegien zur Ausführung zu bringen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1871"/>
  </entry>
</feed>
