Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-3217 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
8.8
2020-06-03 CVE-2020-3215 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device.
local
low complexity
cisco CWE-20
6.7
2020-06-03 CVE-2020-3214 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges.
local
low complexity
cisco CWE-20
6.7
2020-06-03 CVE-2020-3206 Improper Input Validation vulnerability in Cisco IOS XE 16.10.1/16.10.1E/16.10.1S
A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device.
low complexity
cisco CWE-20
4.7
2020-06-03 CVE-2020-3204 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-20
6.7
2020-06-03 CVE-2020-3201 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system.
local
low complexity
cisco CWE-20
6.0
2020-06-03 CVE-2020-3322 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3
2020-06-03 CVE-2020-3321 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3
2020-06-03 CVE-2020-3319 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3
2020-06-02 CVE-2020-3623 Improper Input Validation vulnerability in Qualcomm Sm8250 Firmware and Sxr2130 Firmware
kernel failure due to load failures while running v1 path directly via kernel in Snapdragon Mobile in SM8250, SXR2130
local
low complexity
qualcomm CWE-20
7.8