Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2021-1432

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability...

7.3CVSS

7.2AI Score

0.0004EPSS

2021-03-24 08:15 PM
39
cve
cve

CVE-2021-1433

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic. An attacker could exploit this vulner...

8.1CVSS

8.6AI Score

0.003EPSS

2021-03-24 08:15 PM
47
cve
cve

CVE-2021-1434

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulner...

6CVSS

5.9AI Score

0.0004EPSS

2021-03-24 08:15 PM
36
cve
cve

CVE-2021-1435

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted requ...

7.2CVSS

7.4AI Score

0.002EPSS

2021-03-24 08:15 PM
61
In Wild
cve
cve

CVE-2021-1436

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could e...

4.4CVSS

4.5AI Score

0.0004EPSS

2021-03-24 08:15 PM
37
cve
cve

CVE-2021-1437

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an unrestricted Trivial File Transfer Protocol (TFTP) configurat...

7.5CVSS

7.3AI Score

0.002EPSS

2021-03-24 08:15 PM
40
cve
cve

CVE-2021-1438

A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute wi...

5.5CVSS

5.7AI Score

0.0004EPSS

2021-05-06 01:15 PM
23
2
cve
cve

CVE-2021-1439

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of incoming mDN...

7.4CVSS

7.2AI Score

0.001EPSS

2021-03-24 08:15 PM
41
cve
cve

CVE-2021-1441

A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Series Industrial Integrated Services Routers and Cisco ESR6300 Embedded Series Routers could allow an authenticated, local attacker to execute unsigned code at system boot time. This vulnerability is du...

6.7CVSS

6.6AI Score

0.0004EPSS

2021-03-24 08:15 PM
48
6
cve
cve

CVE-2021-1442

A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device. The vulnerability is due to insufficient protection of se...

7.8CVSS

7.7AI Score

0.0004EPSS

2021-03-24 08:15 PM
40
cve
cve

CVE-2021-1443

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly sanitizes values that are p...

7.2CVSS

7.1AI Score

0.002EPSS

2021-03-24 08:15 PM
50
cve
cve

CVE-2021-1445

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to lack of proper input validati...

8.6CVSS

7.5AI Score

0.001EPSS

2021-04-29 06:15 PM
51
2
cve
cve

CVE-2021-1446

A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a logic error that occurs when an affected d...

8.6CVSS

7.5AI Score

0.001EPSS

2021-03-24 08:15 PM
44
2
cve
cve

CVE-2021-1447

A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password generation algorithm. An atta...

6.7CVSS

6.9AI Score

0.0004EPSS

2021-05-06 01:15 PM
27
2
cve
cve

CVE-2021-1448

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is running in multi-instance mode. This vulnerability is due to i...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-04-29 06:15 PM
28
4
cve
cve

CVE-2021-1449

A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code that manages system startup processes. An attacker could exploit ...

6.7CVSS

6.5AI Score

0.0004EPSS

2021-03-24 08:15 PM
34
cve
cve

CVE-2021-1450

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credential...

5.5CVSS

5.3AI Score

0.0004EPSS

2021-02-24 08:15 PM
45
3
cve
cve

CVE-2021-1451

A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affe...

9.8CVSS

9.9AI Score

0.004EPSS

2021-03-24 08:15 PM
50
3
cve
cve

CVE-2021-1452

A vulnerability in the ROM Monitor (ROMMON) of Cisco IOS XE Software for Cisco Catalyst IE3200, IE3300, and IE3400 Rugged Series Switches, Cisco Catalyst IE3400 Heavy Duty Series Switches, and Cisco Embedded Services 3300 Series Switches could allow an unauthenticated, physical attacker to execute ...

6.8CVSS

6.6AI Score

0.001EPSS

2021-03-24 08:15 PM
38
cve
cve

CVE-2021-1453

A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vulnerability is due to an improper check in the code function...

6.8CVSS

6.7AI Score

0.001EPSS

2021-03-24 08:15 PM
39
3
cve
cve

CVE-2021-1454

Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker could exploit these vu...

6.7CVSS

6.5AI Score

0.0004EPSS

2021-03-24 08:15 PM
41
2
cve
cve

CVE-2021-1455

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation...

4.8CVSS

5AI Score

0.001EPSS

2021-04-29 06:15 PM
34
4
cve
cve

CVE-2021-1456

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation...

4.8CVSS

5AI Score

0.001EPSS

2021-04-29 06:15 PM
34
4
cve
cve

CVE-2021-1457

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation...

4.8CVSS

5AI Score

0.001EPSS

2021-04-29 06:15 PM
40
4
cve
cve

CVE-2021-1458

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation...

4.8CVSS

5AI Score

0.001EPSS

2021-04-29 06:15 PM
34
4
cve
cve

CVE-2021-1459

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-...

9.8CVSS

9.7AI Score

0.002EPSS

2021-04-08 04:15 AM
94
8
cve
cve

CVE-2021-1460

A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, remote attacker to cause a denial of se...

7.5CVSS

7.5AI Score

0.002EPSS

2021-03-24 08:15 PM
41
cve
cve

CVE-2021-1463

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface do...

6.1CVSS

5.9AI Score

0.002EPSS

2021-04-08 04:15 AM
49
2
cve
cve

CVE-2021-1467

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is due to improper authorization checks. An attacker could exploit this vulnerability by sending a crafted request to the Cisco Webex Meetings c...

4.3CVSS

4.5AI Score

0.001EPSS

2021-04-08 04:15 AM
4726
4
cve
cve

CVE-2021-1468

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For mor...

9.8CVSS

9.7AI Score

0.003EPSS

2021-05-06 01:15 PM
28
4
cve
cve

CVE-2021-1469

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, o...

9.9CVSS

8.7AI Score

0.001EPSS

2021-03-24 08:15 PM
54
4
cve
cve

CVE-2021-1471

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, o...

9.9CVSS

8.1AI Score

0.001EPSS

2021-03-24 08:15 PM
82
3
cve
cve

CVE-2021-1472

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details secti...

9.8CVSS

9.9AI Score

0.966EPSS

2021-04-08 04:15 AM
133
13
cve
cve

CVE-2021-1473

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details secti...

9.8CVSS

9.9AI Score

0.722EPSS

2021-04-08 04:15 AM
174
11
cve
cve

CVE-2021-1474

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section...

8.6CVSS

8.6AI Score

0.001EPSS

2021-04-08 04:15 AM
46
4
cve
cve

CVE-2021-1475

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section...

6.5CVSS

4.8AI Score

0.001EPSS

2021-04-08 04:15 AM
49
2
cve
cve

CVE-2021-1476

A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to insu...

6.7CVSS

6.8AI Score

0.0004EPSS

2021-04-29 06:15 PM
33
10
cve
cve

CVE-2021-1477

A vulnerability in an access control mechanism of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access services beyond the scope of their authorization. This vulnerability is due to insufficient enforcement of access control in the affected softwa...

4.3CVSS

4.6AI Score

0.001EPSS

2021-04-29 06:15 PM
36
7
cve
cve

CVE-2021-1478

A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on a...

6.5CVSS

6.4AI Score

0.001EPSS

2021-05-06 01:15 PM
42
cve
cve

CVE-2021-1479

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section...

9.8CVSS

9.7AI Score

0.003EPSS

2021-04-08 04:15 AM
63
3
cve
cve

CVE-2021-1480

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these vulnerabilities, see the Details section...

7.8CVSS

8.6AI Score

0.001EPSS

2021-04-08 04:15 AM
64
3
cve
cve

CVE-2021-1485

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges on the underlying Linux operating system (OS) of an affected device. This vulnerability is due to insufficient input validation of com...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-04-08 04:15 AM
65
cve
cve

CVE-2021-1486

A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A su...

5.3CVSS

5.2AI Score

0.001EPSS

2021-05-06 01:15 PM
31
5
cve
cve

CVE-2021-1487

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability is due to insufficient validation of user-supplied ...

8.8CVSS

9AI Score

0.002EPSS

2021-05-22 07:15 AM
65
cve
cve

CVE-2021-1488

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating system (OS). This vuln...

6.7CVSS

6.4AI Score

0.0004EPSS

2021-04-29 06:15 PM
41
11
cve
cve

CVE-2021-1489

A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exhaust filesystem resources, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to the insufficient manag...

6.5CVSS

6.5AI Score

0.001EPSS

2021-04-29 06:15 PM
23
5
cve
cve

CVE-2021-1490

A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper v...

6.1CVSS

6AI Score

0.002EPSS

2021-05-06 01:15 PM
50
cve
cve

CVE-2021-1493

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary check...

8.5CVSS

7.2AI Score

0.001EPSS

2021-04-29 06:15 PM
64
8
cve
cve

CVE-2021-1495

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this v...

5.8CVSS

6.5AI Score

0.001EPSS

2021-04-29 06:15 PM
39
11
cve
cve

CVE-2021-1496

Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute ...

7.8CVSS

7.7AI Score

0.0004EPSS

2021-05-06 01:15 PM
33
Total number of security vulnerabilities6090