Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-3284 Unspecified vulnerability in Cisco products
A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device.
network
cisco
critical
9.3
2020-11-06 CVE-2020-27129 Argument Injection or Modification vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the remote management feature of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to inject arbitrary commands and potentially gain elevated privileges.
local
low complexity
cisco CWE-88
6.7
2020-11-06 CVE-2020-27128 Path Traversal vulnerability in Cisco Sd-Wan
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system.
network
low complexity
cisco CWE-22
6.5
2020-11-06 CVE-2020-27123 Unspecified vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device.
local
low complexity
cisco
5.5
2020-11-06 CVE-2020-27122 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-269
7.2
2020-11-06 CVE-2020-27121 Improper Handling of Exceptional Conditions vulnerability in Cisco Unified Communications Manager IM and Presence Service 12.5(1)
A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
6.5
2020-11-06 CVE-2020-26086 Exposure of Resource to Wrong Sphere vulnerability in Cisco Telepresence Collaboration Endpoint
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device.
network
low complexity
cisco CWE-668
4.3
2020-11-06 CVE-2020-26084 Exposure of Resource to Wrong Sphere vulnerability in Cisco Edge FOG Fabric
A vulnerability in the REST API of Cisco Edge Fog Fabric could allow an authenticated, remote attacker to access files outside of their authorization sphere on an affected device.
network
low complexity
cisco CWE-668
6.5
2020-11-06 CVE-2020-26083 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
4.8
2020-10-21 CVE-2020-3599 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
6.1