<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_cisco</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:13:53 +0000</lastBuildDate>
    <item>
      <title>cisco-sa-20170317-cmp — Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170317-cmp</link>
      <description>&lt;p&gt;A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.&#13;
&#13;
The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors:&#13;
&#13;
 The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and&#13;
The incorrect processing of malformed CMP-specific Telnet options.&#13;
  An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.&#13;
&#13;
The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors:&#13;
&#13;
 The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and&#13;
The incorrect processing of malformed CMP-specific Telnet options.&#13;
  An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170317-cmp</guid>
      <pubDate>Fri, 17 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170320-ani — Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Registrar Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170320-ani</link>
      <description>&lt;p&gt;A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics:&#13;
&#13;
Running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature&#13;
Configured as an autonomic registrar&#13;
Has a whitelist configured&#13;
An exploit could allow the attacker to cause the affected device to reload.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
Note: Also see the companion advisory for affected devices that support Autonomic Networking: Cisco IOS and IOS XE Software IPv6 Denial of Service Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170320-aniipv6&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics:&#13;
&#13;
Running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature&#13;
Configured as an autonomic registrar&#13;
Has a whitelist configured&#13;
An exploit could allow the attacker to cause the affected device to reload.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
Note: Also see the companion advisory for affected devices that support Autonomic Networking: Cisco IOS and IOS XE Software IPv6 Denial of Service Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170320-aniipv6&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170320-ani</guid>
      <pubDate>Mon, 20 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170320-aniipv6 — Cisco IOS and IOS XE Software IPv6 Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170320-aniipv6</link>
      <description>&lt;p&gt;A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to a device that is running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature.&#13;
&#13;
A device must meet two conditions to be affected by this vulnerability:&#13;
&#13;
The device must be running a version of Cisco IOS Software or Cisco IOS XE Software that supports ANI (regardless of whether ANI is configured)&#13;
The device must have a reachable IPv6 interface&#13;
An exploit could allow the attacker to cause the affected device to reload.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There is a workaround that addresses this vulnerability.&#13;
&#13;
&#13;
&#13;
Note: Also see the companion advisory for affected devices that are configured as an autonomic registrar: Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Registrar Denial of Service Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170320-ani&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to a device that is running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature.&#13;
&#13;
A device must meet two conditions to be affected by this vulnerability:&#13;
&#13;
The device must be running a version of Cisco IOS Software or Cisco IOS XE Software that supports ANI (regardless of whether ANI is configured)&#13;
The device must have a reachable IPv6 interface&#13;
An exploit could allow the attacker to cause the affected device to reload.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There is a workaround that addresses this vulnerability.&#13;
&#13;
&#13;
&#13;
Note: Also see the companion advisory for affected devices that are configured as an autonomic registrar: Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Registrar Denial of Service Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170320-ani&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170320-aniipv6</guid>
      <pubDate>Mon, 20 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170322-dhcpc — Cisco IOS and IOS XE Software DHCP Client Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170322-dhcpc</link>
      <description>&lt;p&gt;A vulnerability in the DHCP client implementation of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability occurs during the parsing of a crafted DHCP packet. An attacker could exploit this vulnerability by sending crafted DHCP packets to an affected device that is configured as a DHCP client. A successful exploit could allow the attacker to cause a reload of an affected device, resulting in a DoS condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the DHCP client implementation of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.&#13;
&#13;
The vulnerability occurs during the parsing of a crafted DHCP packet. An attacker could exploit this vulnerability by sending crafted DHCP packets to an affected device that is configured as a DHCP client. A successful exploit could allow the attacker to cause a reload of an affected device, resulting in a DoS condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170322-dhcpc</guid>
      <pubDate>Wed, 22 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170322-l2tp — Cisco IOS and IOS XE Software Layer 2 Tunneling Protocol Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170322-l2tp</link>
      <description>&lt;p&gt;A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to insufficient validation of L2TP packets. An attacker could exploit this vulnerability by sending a crafted L2TP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to insufficient validation of L2TP packets. An attacker could exploit this vulnerability by sending a crafted L2TP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170322-l2tp</guid>
      <pubDate>Wed, 22 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170322-webui — Cisco IOS XE Software Web User Interface Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170322-webui</link>
      <description>&lt;p&gt;A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.&#13;
&#13;
To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.&#13;
&#13;
To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170322-webui</guid>
      <pubDate>Wed, 22 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170322-xeci — Cisco IOS XE Software HTTP Command Injection Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170322-xeci</link>
      <description>&lt;p&gt;A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.&#13;
&#13;
The vulnerability is due to insufficient input validation of HTTP parameters supplied by the user. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the affected web page parameter. The user must be authenticated to access the affected parameter. A successful exploit could allow the attacker to execute commands with root privileges.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges.&#13;
&#13;
The vulnerability is due to insufficient input validation of HTTP parameters supplied by the user. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the affected web page parameter. The user must be authenticated to access the affected parameter. A successful exploit could allow the attacker to execute commands with root privileges.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170322-xeci</guid>
      <pubDate>Wed, 22 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170322-ztp — Cisco IOS XE Software for Cisco ASR 920 Series Routers Zero Touch Provisioning Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170322-ztp</link>
      <description>&lt;p&gt;A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to a format string vulnerability when processing a crafted DHCP packet for Zero Touch Provisioning. An attacker could exploit this vulnerability by sending a specially crafted DHCP packet to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload.&#13;
&#13;
The vulnerability is due to a format string vulnerability when processing a crafted DHCP packet for Zero Touch Provisioning. An attacker could exploit this vulnerability by sending a specially crafted DHCP packet to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the March 22, 2017, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes five Cisco Security Advisories that describe five vulnerabilities. All the vulnerabilities have a Security Impact Rating of High. For a complete list of the advisories and links to them, see Cisco Event Response: March 2017 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-60851&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170322-ztp</guid>
      <pubDate>Wed, 22 Mar 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170419-energywise — Cisco IOS and IOS XE Software EnergyWise Denial of Service Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170419-energywise</link>
      <description>&lt;p&gt;Multiple vulnerabilities in the EnergyWise module of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition.&#13;
&#13;
These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in the EnergyWise module of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition.&#13;
&#13;
These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170419-energywise</guid>
      <pubDate>Wed, 19 Apr 2017 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-20170621-piwf — Cisco Prime Infrastructure Web Framework Code Cross-Site Scripting Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20170621-piwf</link>
      <description>&lt;p&gt;A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.&#13;
&#13;
The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request. An exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.&#13;
&#13;
For additional information about cross-site scripting attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectors [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoAppliedMitigationBulletin/cisco-amb-20060922-understanding-xss&amp;#34;].&#13;
&#13;
There are no workarounds that address this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.&#13;
&#13;
The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request. An exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.&#13;
&#13;
For additional information about cross-site scripting attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectors [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoAppliedMitigationBulletin/cisco-amb-20060922-understanding-xss&amp;#34;].&#13;
&#13;
There are no workarounds that address this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20170621-piwf</guid>
      <pubDate>Wed, 21 Jun 2017 16:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
