Cisco NX-OS Software NX-API Denial of Service (CVE-2020-3170)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to inc ...

Continue Reading
Cisco NX-OS Software NX-API Cross-Site Request Forgery (CVE-2021-1227)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerab ...

Continue Reading
Cisco NX-OS Software NX-API Command Injection (CVE-2022-20650)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient ...

Continue Reading
Cisco NX-OS Software CLI Bypass to Internal Service (CVE-2019-1726)

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vul ...

Continue Reading
Cisco NX-OS Software NX-API Privilege Escalation (CVE-2018-0330)

A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco NX-OS Software could allow an authenticated, remote attacker to execute commands ...

Continue Reading
Cisco NX-OS Software NX-API Denial of Service (CVE-2019-1968)

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause an NX-API system process to unexpectedly restart. The vulnerability is due to inc ...

Continue Reading
Cisco NX-OS Software NX-API Sandbox Cross-Site Scripting (CVE-2019-1733)

A vulnerability in the NX API (NX-API) Sandbox interface for Cisco NX- OS Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the NX ...

Continue Reading
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with acc ...

Continue Reading

Back to Main

Subscribe for the latest news: