Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2021-04-08 CVE-2021-1399 Authentication Bypass by Assumed-Immutable Data vulnerability in Cisco Unified Communications Manager
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system without proper authorization.
network
low complexity
cisco CWE-302
4.3
2021-04-08 CVE-2021-1386 Uncontrolled Search Path Element vulnerability in Cisco products
A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected Windows system.
local
low complexity
cisco CWE-427
7.8
2021-04-08 CVE-2021-1380 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an interface user.
network
low complexity
cisco CWE-79
6.1
2021-04-08 CVE-2021-1362 Code Injection vulnerability in Cisco products
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-94
8.8
2021-04-08 CVE-2021-1309 Memory Leak vulnerability in Cisco products
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers.
low complexity
cisco CWE-401
8.8
2021-04-08 CVE-2021-1308 Memory Leak vulnerability in Cisco products
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers.
low complexity
cisco CWE-401
7.4
2021-04-08 CVE-2021-1251 Memory Leak vulnerability in Cisco products
Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers.
low complexity
cisco CWE-401
7.4
2021-04-08 CVE-2021-1137 Improper Input Validation vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system.
local
low complexity
cisco CWE-20
7.8
2021-03-24 CVE-2021-1423 Exposure of Resource to Wrong Sphere vulnerability in Cisco products
A vulnerability in the implementation of a CLI command in Cisco Aironet Access Points (AP) could allow an authenticated, local attacker to overwrite files in the flash memory of the device.
local
low complexity
cisco CWE-668
4.4
2021-03-24 CVE-2021-1418 Improper Null Termination vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-170
6.5