Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2023-20224

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input validation of user-supplied CLI arguments. An...

7.8CVSS

7.8AI Score

0.0004EPSS

2023-08-16 10:15 PM
79
cve
cve

CVE-2023-20209

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote...

7.2CVSS

7.5AI Score

0.001EPSS

2023-08-16 09:15 PM
71
cve
cve

CVE-2023-20135

A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO...

7CVSS

7AI Score

0.0004EPSS

2023-09-13 05:15 PM
34
cve
cve

CVE-2023-20108

A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service outage for all Cisco Unified CM IM&P users who are attempting to authenticate to the...

7.5CVSS

7.7AI Score

0.001EPSS

2023-06-28 03:15 PM
820
cve
cve

CVE-2023-20085

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to...

6.1CVSS

5.9AI Score

0.001EPSS

2023-03-01 08:15 AM
82
cve
cve

CVE-2023-20083

A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and...

8.6CVSS

8.4AI Score

0.001EPSS

2023-11-01 06:15 PM
46
cve
cve

CVE-2023-20075

Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a...

6.7CVSS

6.9AI Score

0.0005EPSS

2023-03-01 08:15 AM
59
cve
cve

CVE-2023-20048

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software. This vulnerability.....

9.9CVSS

9.4AI Score

0.001EPSS

2023-11-01 06:15 PM
82
cve
cve

CVE-2023-20044

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by persuading support to update settings which call the insecure script. A...

7.3CVSS

7AI Score

0.0004EPSS

2023-01-20 07:15 AM
28
cve
cve

CVE-2023-20038

A vulnerability in the monitoring application of Cisco Industrial Network Director could allow an authenticated, local attacker to access a static secret key used to store both local data and credentials for accessing remote systems. This vulnerability is due to a static key value stored in the...

8.8CVSS

8.3AI Score

0.0004EPSS

2023-01-20 07:15 AM
53
cve
cve

CVE-2023-20010

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This....

8.8CVSS

8.7AI Score

0.001EPSS

2023-01-20 07:15 AM
54
cve
cve

CVE-2022-20965

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within the web-based...

5.4CVSS

5.4AI Score

0.001EPSS

2023-01-20 07:15 AM
452
2
cve
cve

CVE-2022-20964

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the...

8.8CVSS

8.8AI Score

0.001EPSS

2023-01-20 07:15 AM
500
2
cve
cve

CVE-2022-20961

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF...

8.8CVSS

8.8AI Score

0.001EPSS

2022-11-04 06:15 PM
47
7
cve
cve

CVE-2022-20962

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit...

8.8CVSS

8.7AI Score

0.002EPSS

2022-11-04 06:15 PM
34
4
cve
cve

CVE-2022-20946

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory...

8.6CVSS

7.5AI Score

0.002EPSS

2022-11-15 09:15 PM
39
8
cve
cve

CVE-2022-20932

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
35
cve
cve

CVE-2022-20838

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
38
4
cve
cve

CVE-2022-20832

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
56
2
cve
cve

CVE-2023-20267

A vulnerability in the IP geolocation rules of Snort 3 could allow an unauthenticated, remote attacker to potentially bypass IP address restrictions. This vulnerability exists because the configuration for IP geolocation rules is not parsed properly. An attacker could exploit this vulnerability by....

5.3CVSS

5.3AI Score

0.001EPSS

2023-11-01 06:15 PM
33
cve
cve

CVE-2023-20243

A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An.....

8.6CVSS

7.8AI Score

0.001EPSS

2023-09-06 06:15 PM
67
cve
cve

CVE-2023-20206

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are.....

6.1CVSS

5.9AI Score

0.001EPSS

2023-11-01 05:15 PM
23
cve
cve

CVE-2023-20191

A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incomplete support for this feature. An attacker could exploit...

7.5CVSS

7.6AI Score

0.001EPSS

2023-09-13 05:15 PM
31
cve
cve

CVE-2023-20179

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to inject HTML content. This vulnerability is due to improper validation of user-supplied data in element fields. An attacker could...

5.4CVSS

5.3AI Score

0.0005EPSS

2023-09-27 06:15 PM
35
cve
cve

CVE-2023-20133

A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of user-supplied input in Webex Events...

5.4CVSS

5.2AI Score

0.0005EPSS

2023-07-07 08:15 PM
24
cve
cve

CVE-2023-20136

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to execute operations that should require Administrator privileges. The attacker would need valid user credentials. This vulnerability is due to improper...

6.5CVSS

6.5AI Score

0.001EPSS

2023-06-28 03:15 PM
46
cve
cve

CVE-2023-20053

A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user...

6.1CVSS

5.9AI Score

0.001EPSS

2023-03-01 08:15 AM
57
cve
cve

CVE-2023-20041

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are.....

6.1CVSS

5.9AI Score

0.001EPSS

2023-11-01 05:15 PM
25
cve
cve

CVE-2023-20013

Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the affected device to exploit these vulnerabilities. These...

9.1CVSS

9.2AI Score

0.001EPSS

2023-08-16 10:15 PM
37
cve
cve

CVE-2022-20967

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of...

5.4CVSS

5.3AI Score

0.001EPSS

2023-01-20 07:15 AM
458
2
cve
cve

CVE-2022-20960

A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an...

7.5CVSS

7.5AI Score

0.001EPSS

2022-11-04 06:15 PM
61
4
cve
cve

CVE-2022-20949

A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because access to HTTPS endpoints is not properly...

6.5CVSS

5.5AI Score

0.001EPSS

2022-11-15 09:15 PM
36
8
cve
cve

CVE-2022-20941

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to missing authorization for certain resources in the web-based management interface.....

5.3CVSS

5.2AI Score

0.001EPSS

2022-11-15 09:15 PM
39
4
cve
cve

CVE-2022-20937

A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An...

5.3CVSS

5.3AI Score

0.001EPSS

2022-11-04 06:15 PM
53
3
cve
cve

CVE-2022-20917

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulnerability is due to the improper...

4.3CVSS

4.7AI Score

0.001EPSS

2023-09-15 03:15 AM
2816
4
cve
cve

CVE-2022-20872

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
34
4
cve
cve

CVE-2022-20834

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
38
4
cve
cve

CVE-2023-20270

A vulnerability in the interaction between the Server Message Block (SMB) protocol preprocessor and the Snort 3 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS)...

5.8CVSS

5.9AI Score

0.001EPSS

2023-11-01 05:15 PM
23
cve
cve

CVE-2023-20252

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML.....

9.8CVSS

9.7AI Score

0.002EPSS

2023-09-27 06:15 PM
2421
cve
cve

CVE-2023-20170

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the.....

6.7CVSS

6.6AI Score

0.0004EPSS

2023-11-01 06:15 PM
35
cve
cve

CVE-2023-20114

A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability is due to a lack of input sanitation. An attacker could exploit this vulnerability.....

6.5CVSS

6.4AI Score

0.001EPSS

2023-11-01 05:15 PM
29
cve
cve

CVE-2023-20111

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An...

6.5CVSS

6.3AI Score

0.001EPSS

2023-08-16 10:15 PM
24
cve
cve

CVE-2023-20101

A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the....

9.8CVSS

9.8AI Score

0.001EPSS

2023-10-04 05:15 PM
66
cve
cve

CVE-2023-20074

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are.....

6.1CVSS

5.9AI Score

0.001EPSS

2023-11-01 05:15 PM
21
cve
cve

CVE-2023-20043

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker...

6.7CVSS

6.4AI Score

0.0004EPSS

2023-01-20 07:15 AM
38
cve
cve

CVE-2023-20034

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the...

7.5CVSS

7.5AI Score

0.001EPSS

2023-09-27 06:15 PM
30
cve
cve

CVE-2022-20940

A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper implementation of countermeasures against a Bleichenbacher attack on a device that uses....

5.3CVSS

5.5AI Score

0.001EPSS

2022-11-15 09:15 PM
41
7
cve
cve

CVE-2022-20935

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
37
2
cve
cve

CVE-2022-20839

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
35
4
cve
cve

CVE-2022-20833

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are...

4.8CVSS

5AI Score

0.001EPSS

2022-11-15 09:15 PM
34
4
Total number of security vulnerabilities6154