Vulnerabilities > Cisco > IOS XE > 17.3.4a

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-20082 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.
low complexity
cisco
6.8
2023-03-23 CVE-2023-20097 Command Injection vulnerability in Cisco products
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges.
local
low complexity
cisco CWE-77
6.7
2023-02-12 CVE-2023-20076 OS Command Injection vulnerability in Cisco products
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system.
network
low complexity
cisco CWE-78
8.8
2022-04-15 CVE-2022-20676 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges.
local
low complexity
cisco CWE-20
6.7
2022-04-15 CVE-2022-20679 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.7
2022-04-15 CVE-2022-20681 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device.
local
low complexity
cisco
7.8
2022-04-15 CVE-2022-20693 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.
network
low complexity
cisco CWE-78
7.2
2022-04-15 CVE-2022-20718 OS Command Injection vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software.
network
low complexity
cisco CWE-78
7.2
2022-04-15 CVE-2022-20719 Path Traversal vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software.
network
low complexity
cisco CWE-22
7.2
2022-04-15 CVE-2022-20720 Link Following vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software.
network
low complexity
cisco CWE-59
7.2