Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-1418 Improper Null Termination vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-170
6.5
2021-03-24 CVE-2021-1417 Unspecified vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco
6.5
2021-03-24 CVE-2021-1411 Improper Null Termination vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-170
critical
9.9
2021-03-24 CVE-2021-1381 Leftover Debug Code vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console.
low complexity
cisco CWE-489
6.1
2021-03-24 CVE-2021-1376 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XE
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious software image, or execute unsigned binaries on an affected device.
local
low complexity
cisco CWE-347
7.2
2021-03-24 CVE-2021-1375 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XE
Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious software image, or execute unsigned binaries on an affected device.
local
low complexity
cisco CWE-347
7.2
2021-03-24 CVE-2021-1374 Cross-site Scripting vulnerability in Cisco IOS XE
A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
4.8
2021-03-24 CVE-2021-1373 Buffer Over-read vulnerability in Cisco IOS XE
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device.
network
low complexity
cisco CWE-126
8.6
2021-03-24 CVE-2021-1371 Improper Privilege Management vulnerability in Cisco IOS XE Sd-Wan 17.2.0
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration.
low complexity
cisco CWE-269
6.6
2021-03-24 CVE-2021-1356 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
4.3