Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2023-20142

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
20
cve
cve

CVE-2023-20143

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
24
cve
cve

CVE-2023-20144

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
19
cve
cve

CVE-2023-20145

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
22
cve
cve

CVE-2023-20146

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
26
cve
cve

CVE-2023-20147

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
24
cve
cve

CVE-2023-20148

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
21
cve
cve

CVE-2023-20149

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
24
cve
cve

CVE-2023-20150

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
28
cve
cve

CVE-2023-20151

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due t...

6.1CVSS

6AI Score

0.001EPSS

2023-04-05 07:15 PM
25
cve
cve

CVE-2023-20152

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid A...

6.7CVSS

6.8AI Score

0.0004EPSS

2023-04-05 06:15 PM
20
cve
cve

CVE-2023-20153

Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid A...

6.7CVSS

6.8AI Score

0.0004EPSS

2023-04-05 07:15 PM
29
cve
cve

CVE-2023-20155

A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the device to become unresponsive or trigger an unexpected reload. This vulnerability could also allow an attacker with valid user credentials, but not Admin...

7.5CVSS

6.5AI Score

0.001EPSS

2023-11-01 05:15 PM
40
cve
cve

CVE-2023-20156

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
44
cve
cve

CVE-2023-20157

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
25
cve
cve

CVE-2023-20158

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
55
cve
cve

CVE-2023-20159

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
264
cve
cve

CVE-2023-20160

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
57
cve
cve

CVE-2023-20161

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.8AI Score

0.002EPSS

2023-05-18 03:15 AM
57
cve
cve

CVE-2023-20162

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
31
cve
cve

CVE-2023-20163

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected dev...

7.2CVSS

7.1AI Score

0.001EPSS

2023-05-18 03:15 AM
25
cve
cve

CVE-2023-20164

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected dev...

7.2CVSS

7.1AI Score

0.001EPSS

2023-05-18 03:15 AM
21
cve
cve

CVE-2023-20166

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Adm...

6.7CVSS

6.4AI Score

0.0004EPSS

2023-05-18 03:15 AM
30
cve
cve

CVE-2023-20167

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Adm...

6CVSS

5.1AI Score

0.001EPSS

2023-05-18 03:15 AM
37
cve
cve

CVE-2023-20168

A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication attempt if the directed r...

7.1CVSS

6.6AI Score

0.001EPSS

2023-08-23 07:15 PM
69
cve
cve

CVE-2023-20169

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS process to unexpecte...

7.4CVSS

7.3AI Score

0.002EPSS

2023-08-23 07:15 PM
57
cve
cve

CVE-2023-20170

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the a...

6.7CVSS

6.6AI Score

0.0004EPSS

2023-11-01 06:15 PM
35
cve
cve

CVE-2023-20171

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about th...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-05-18 03:15 AM
18
cve
cve

CVE-2023-20172

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about th...

5.4CVSS

5.1AI Score

0.001EPSS

2023-05-18 03:15 AM
18
cve
cve

CVE-2023-20173

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attack...

4.9CVSS

5.2AI Score

0.001EPSS

2023-05-18 03:15 AM
18
cve
cve

CVE-2023-20174

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attack...

4.9CVSS

5.2AI Score

0.001EPSS

2023-05-18 03:15 AM
18
cve
cve

CVE-2023-20175

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on...

8.8CVSS

8.5AI Score

0.0004EPSS

2023-11-01 06:15 PM
46
cve
cve

CVE-2023-20176

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this vulnerability by connecting to an AP on an...

8.6CVSS

8.2AI Score

0.001EPSS

2023-09-27 06:15 PM
32
cve
cve

CVE-2023-20177

A vulnerability in the SSL file policy implementation of Cisco Firepower Threat Defense (FTD) Software that occurs when the SSL/TLS connection is configured with a URL Category and the Snort 3 detection engine could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to ...

4CVSS

4.7AI Score

0.001EPSS

2023-11-01 05:15 PM
33
cve
cve

CVE-2023-20178

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after...

7.8CVSS

7.6AI Score

0.001EPSS

2023-06-28 03:15 PM
2391
cve
cve

CVE-2023-20179

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content. This vulnerability is due to improper validation of user-supplied data in element fields. An attacker could ex...

5.4CVSS

5.3AI Score

0.0005EPSS

2023-09-27 06:15 PM
35
cve
cve

CVE-2023-20180

A vulnerability in the web interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web interface on an affected system. An attack...

4.3CVSS

5AI Score

0.001EPSS

2023-07-07 08:15 PM
32
cve
cve

CVE-2023-20181

A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affe...

6.1CVSS

6.3AI Score

0.001EPSS

2023-08-03 10:15 PM
42
cve
cve

CVE-2023-20182

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vuln...

8.8CVSS

8.9AI Score

0.001EPSS

2023-05-18 03:15 AM
26
cve
cve

CVE-2023-20183

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vuln...

5.4CVSS

5.3AI Score

0.001EPSS

2023-05-18 03:15 AM
21
cve
cve

CVE-2023-20184

Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vuln...

5.4CVSS

5.3AI Score

0.001EPSS

2023-05-18 03:15 AM
23
cve
cve

CVE-2023-20185

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic. This vulnerability is due to an issue with the implementation of the ciphers ...

7.4CVSS

7.3AI Score

0.001EPSS

2023-07-12 02:15 PM
19
cve
cve

CVE-2023-20186

A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Prot...

9.1CVSS

9.2AI Score

0.001EPSS

2023-09-27 06:15 PM
80
cve
cve

CVE-2023-20187

A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vul...

8.6CVSS

7.6AI Score

0.001EPSS

2023-09-27 06:15 PM
50
cve
cve

CVE-2023-20188

A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attacker to conduct a stored cross-site scri...

4.8CVSS

4.8AI Score

0.001EPSS

2023-06-28 03:15 PM
59
cve
cve

CVE-2023-20189

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due t...

9.8CVSS

9.7AI Score

0.002EPSS

2023-05-18 03:15 AM
39
cve
cve

CVE-2023-20190

A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range ...

5.8CVSS

5.3AI Score

0.001EPSS

2023-09-13 05:15 PM
30
cve
cve

CVE-2023-20191

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incomplete support for this feature. An attacker could exploit th...

7.5CVSS

7.6AI Score

0.001EPSS

2023-09-13 05:15 PM
31
cve
cve

CVE-2023-20192

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cis...

9.6CVSS

7.4AI Score

0.0004EPSS

2023-06-28 03:15 PM
694
cve
cve

CVE-2023-20193

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator...

6.7CVSS

6.5AI Score

0.0004EPSS

2023-09-07 08:15 PM
42
Total number of security vulnerabilities6057