<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 12:35:12 +0000</lastBuildDate>
    <item>
      <title>certfr-2018-avi-458 — De multiples vulnérabilités ont été découvertes dans les produits Cisco.
Elles permettent à un attaquant de provoquer u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-458</link>
      <description>certfr-2018-avi-458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-458</guid>
    </item>
    <item>
      <title>cisco-sa-20180926-iosxe-cmdinj — Cisco IOS XE Software Command Injection Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20180926-iosxe-cmdinj</link>
      <description>&lt;p&gt;Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.&#13;
&#13;
The vulnerabilities exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-iosxe-cmdinj [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-iosxe-cmdinj&amp;#34;]&#13;
  This advisory is part of the September 26, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 12 Cisco Security Advisories that describe 13 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: September 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundle…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.&#13;
&#13;
The vulnerabilities exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-iosxe-cmdinj [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180926-iosxe-cmdinj&amp;#34;]&#13;
  This advisory is part of the September 26, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 12 Cisco Security Advisories that describe 13 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: September 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundle…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20180926-iosxe-cmdinj</guid>
    </item>
    <item>
      <title>cnvd-2018-20300</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-20300</link>
      <description>cnvd-2018-20300</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-20300</guid>
    </item>
    <item>
      <title>EUVD-2026-204408</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-204408</link>
      <description>EUVD-2026-204408</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-204408</guid>
    </item>
    <item>
      <title>fkie_cve-2018-0477</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-0477</link>
      <description>&lt;p&gt;A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-0477</guid>
    </item>
    <item>
      <title>GHSA-x627-jg77-frxc</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x627-jg77-frxc</link>
      <description>&lt;p&gt;A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exist because the affected software improperly sanitizes command arguments, failing to prevent access to certain internal data structures on an affected device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain custom arguments. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the affected device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x627-jg77-frxc</guid>
    </item>
    <item>
      <title>gsd-2018-0477</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-0477</link>
      <description>gsd-2018-0477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-0477</guid>
    </item>
  </channel>
</rss>
