Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-11-18 CVE-2020-26078 Path Traversal vulnerability in Cisco IOT Field Network Director
A vulnerability in the file system of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to overwrite files on an affected system.
network
low complexity
cisco CWE-22
6.5
2020-11-18 CVE-2020-26077 Improper Privilege Management vulnerability in Cisco IOT Field Network Director
A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system.
network
low complexity
cisco CWE-269
4.3
2020-11-18 CVE-2020-26076 Information Exposure vulnerability in Cisco IOT Field Network Director
A vulnerability in Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive database information on an affected device.
network
low complexity
cisco CWE-200
7.5
2020-11-18 CVE-2020-26075 SQL Injection vulnerability in Cisco IOT Field Network Director
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to gain access to the back-end database of an affected device.
network
low complexity
cisco CWE-89
8.8
2020-11-18 CVE-2020-26072 Improper Privilege Management vulnerability in Cisco IOT Field Network Director
A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain.
network
low complexity
cisco CWE-269
8.7
2020-11-18 CVE-2020-26068 Authorization Bypass Through User-Controlled Key vulnerability in Cisco Roomos and Telepresence Collaboration Endpoint
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device.
network
low complexity
cisco CWE-639
6.5
2020-11-17 CVE-2020-27131 Deserialization of Untrusted Data vulnerability in Cisco Security Manager
Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.
network
low complexity
cisco CWE-502
critical
9.8
2020-11-17 CVE-2020-27130 Unspecified vulnerability in Cisco Security Manager
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information.
network
low complexity
cisco
critical
9.1
2020-11-17 CVE-2020-27125 Improper Input Validation vulnerability in Cisco Security Manager
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information on an affected system.
network
low complexity
cisco CWE-20
critical
9.8
2020-11-12 CVE-2020-26070 Improper Resource Shutdown or Release vulnerability in Cisco IOS XR
A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-404
8.6