Vulnerabilities > Cisco > ASR 920 4SZ D

DATE CVE VULNERABILITY TITLE RISK
2017-09-07 CVE-2017-6795 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device.
local
cisco CWE-20
4.7
2017-04-07 CVE-2017-6603 Denial of Service vulnerability in Cisco ASR 900 Series Firmware 15.4(3)S3.15
A vulnerability in Cisco ASR 903 or ASR 920 Series Devices running with an RSP2 card could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on a targeted system because of incorrect IPv6 Packet Processing.
low complexity
cisco
6.1
2017-03-22 CVE-2017-3859 Use of Externally-Controlled Format String vulnerability in Cisco IOS XE
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-134
7.8