Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2021-34721

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section ...

6.7CVSS

7AI Score

0.0004EPSS

2021-09-09 05:15 AM
43
cve
cve

CVE-2021-34722

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section ...

6.7CVSS

7AI Score

0.0004EPSS

2021-09-09 05:15 AM
37
cve
cve

CVE-2021-34723

A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vulnerability is due to insufficient validation of specific CLI command parameter...

6.7CVSS

6.6AI Score

0.0004EPSS

2021-09-23 03:15 AM
37
cve
cve

CVE-2021-34724

A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user. This vulnerability is ...

6CVSS

6.2AI Score

0.0004EPSS

2021-09-23 03:15 AM
29
cve
cve

CVE-2021-34725

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An a...

6.7CVSS

6.6AI Score

0.0004EPSS

2021-09-23 03:15 AM
35
cve
cve

CVE-2021-34726

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation on certain CLI...

6.7CVSS

6.6AI Score

0.0004EPSS

2021-09-23 03:15 AM
30
cve
cve

CVE-2021-34727

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit thi...

9.8CVSS

9.9AI Score

0.02EPSS

2021-09-23 03:15 AM
52
cve
cve

CVE-2021-34728

Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

7.8CVSS

7.4AI Score

0.0004EPSS

2021-09-09 05:15 AM
48
cve
cve

CVE-2021-34729

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI com...

6.7CVSS

6.8AI Score

0.0004EPSS

2021-09-23 03:15 AM
34
cve
cve

CVE-2021-34730

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condi...

9.8CVSS

9AI Score

0.006EPSS

2021-08-18 08:15 PM
104
19
cve
cve

CVE-2021-34731

A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently valid...

4.8CVSS

5.1AI Score

0.001EPSS

2021-11-04 04:15 PM
23
cve
cve

CVE-2021-34732

A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input...

6.1CVSS

5.9AI Score

0.002EPSS

2021-09-02 03:15 AM
56
cve
cve

CVE-2021-34733

A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive informat...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-09-02 03:15 AM
36
cve
cve

CVE-2021-34734

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of memory reso...

6.5CVSS

6.5AI Score

0.001EPSS

2021-08-18 08:15 PM
34
cve
cve

CVE-2021-34735

Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilitie...

8.8CVSS

8.2AI Score

0.002EPSS

2021-10-06 08:15 PM
24
cve
cve

CVE-2021-34736

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to cause the web-based management interface to unexpectedly restart. The vulnerability is due to insufficient input validation on the web-ba...

7.5CVSS

7.4AI Score

0.001EPSS

2021-10-21 03:15 AM
37
cve
cve

CVE-2021-34737

A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because certain DHCPv4 messages are improperly ...

7.5CVSS

7.5AI Score

0.002EPSS

2021-09-09 05:15 AM
35
cve
cve

CVE-2021-34738

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this a...

6.1CVSS

5.9AI Score

0.001EPSS

2021-10-21 03:15 AM
32
cve
cve

CVE-2021-34739

A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface of an affected device. This vulnerabilit...

8.1CVSS

8.4AI Score

0.003EPSS

2021-11-04 04:15 PM
83
cve
cve

CVE-2021-34740

A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect error ha...

7.4CVSS

7.4AI Score

0.001EPSS

2021-09-23 03:15 AM
48
cve
cve

CVE-2021-34741

A vulnerability in the email scanning algorithm of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of in...

7.5CVSS

7.6AI Score

0.002EPSS

2021-11-04 04:15 PM
61
cve
cve

CVE-2021-34742

A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability is due to insufficient validation o...

6.1CVSS

5.9AI Score

0.001EPSS

2021-10-06 08:15 PM
32
cve
cve

CVE-2021-34743

A vulnerability in the application integration feature of Cisco Webex Software could allow an unauthenticated, remote attacker to authorize an external application to integrate with and access a user's account without that user's express consent. This vulnerability is due to improper validation of ...

7.1CVSS

7AI Score

0.001EPSS

2021-10-21 03:15 AM
35
2
cve
cve

CVE-2021-34744

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of th...

4.9CVSS

5.2AI Score

0.001EPSS

2021-10-06 08:15 PM
26
cve
cve

CVE-2021-34745

A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM privileges. This vulnerability is due to the .NET Agent Coordinator Service executing code with SYSTEM privileges. An attacker with local access to a dev...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-08-18 08:15 PM
37
cve
cve

CVE-2021-34746

A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator. This vulnerability is due ...

9.8CVSS

9.2AI Score

0.009EPSS

2021-09-02 03:15 AM
60
cve
cve

CVE-2021-34748

A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabi...

8.8CVSS

9AI Score

0.001EPSS

2021-10-06 08:15 PM
42
2
cve
cve

CVE-2021-34749

A vulnerability in Server Name Identification (SNI) request filtering of Cisco Web Security Appliance (WSA), Cisco Firepower Threat Defense (FTD), and the Snort detection engine could allow an unauthenticated, remote attacker to bypass filtering technology on an affected device and exfiltrate data ...

8.6CVSS

8.4AI Score

0.003EPSS

2021-08-18 08:15 PM
61
5
cve
cve

CVE-2021-34754

Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic. These vulnerabilities are due to incomplete processing du...

7.5CVSS

7.7AI Score

0.001EPSS

2021-10-27 07:15 PM
40
cve
cve

CVE-2021-34755

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.

7.8CVSS

7.8AI Score

0.0004EPSS

2021-10-27 07:15 PM
41
cve
cve

CVE-2021-34756

Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.

7.8CVSS

7.8AI Score

0.0004EPSS

2021-10-27 07:15 PM
32
cve
cve

CVE-2021-34757

Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnerabilities, see the Details section of th...

5.5CVSS

5.5AI Score

0.0004EPSS

2021-10-06 08:15 PM
24
cve
cve

CVE-2021-34758

A vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient ...

4.4CVSS

4.3AI Score

0.0004EPSS

2021-10-06 08:15 PM
58
cve
cve

CVE-2021-34759

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the ...

4.8CVSS

4.9AI Score

0.001EPSS

2021-09-02 03:15 AM
37
cve
cve

CVE-2021-34760

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the...

4.8CVSS

4.9AI Score

0.001EPSS

2021-10-21 03:15 AM
62
cve
cve

CVE-2021-34761

A vulnerability in Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite or append arbitrary data to system files using root-level privileges. The attacker must have administrative credentials on the device. This vulnerability is due to incomplete v...

6CVSS

6.1AI Score

0.0004EPSS

2021-10-27 07:15 PM
28
cve
cve

CVE-2021-34762

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The vulnerability is due to ins...

8.1CVSS

7.8AI Score

0.002EPSS

2021-10-27 07:15 PM
35
cve
cve

CVE-2021-34763

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this adv...

4.8CVSS

5.2AI Score

0.001EPSS

2021-10-27 07:15 PM
36
cve
cve

CVE-2021-34764

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabilities, see the Details section of this adv...

6.1CVSS

6AI Score

0.001EPSS

2021-10-27 07:15 PM
40
cve
cve

CVE-2021-34765

A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based access control (RBAC) filters are not a...

4.3CVSS

4.6AI Score

0.001EPSS

2021-09-02 03:15 AM
37
cve
cve

CVE-2021-34766

A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to insufficient authorization of the Syst...

8.8CVSS

8.5AI Score

0.003EPSS

2021-10-06 08:15 PM
24
cve
cve

CVE-2021-34767

A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that ...

7.4CVSS

7.3AI Score

0.001EPSS

2021-09-23 03:15 AM
40
cve
cve

CVE-2021-34768

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...

8.6CVSS

7.7AI Score

0.002EPSS

2021-09-23 03:15 AM
49
cve
cve

CVE-2021-34769

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...

8.6CVSS

7.7AI Score

0.002EPSS

2021-09-23 03:15 AM
46
cve
cve

CVE-2021-34770

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a den...

10CVSS

7.7AI Score

0.002EPSS

2021-09-23 03:15 AM
49
cve
cve

CVE-2021-34771

A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. This vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulner...

5.5CVSS

5.2AI Score

0.0004EPSS

2021-09-09 05:15 AM
56
cve
cve

CVE-2021-34772

A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker to redirect users to a malicious webpage. This vulnerability is due to improper validation of URL paths in the web-based management interface. An attacker could exploit this vulner...

6.1CVSS

6.2AI Score

0.001EPSS

2021-10-06 08:15 PM
33
cve
cve

CVE-2021-34773

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticat...

6.5CVSS

6.8AI Score

0.001EPSS

2021-11-04 04:15 PM
30
cve
cve

CVE-2021-34774

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect sensitive data when ...

4.9CVSS

4.8AI Score

0.001EPSS

2021-11-04 04:15 PM
49
cve
cve

CVE-2021-34775

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 Series Smart Switches. An unauthenticated, adjacent attacker could perform the following: Execute code on the affected device or cause it to reload unexpectedly Cause LLDP database...

4.3CVSS

5AI Score

0.001EPSS

2021-10-06 08:15 PM
29
Total number of security vulnerabilities6090