Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-3604 Out-of-bounds Write vulnerability in Cisco Webex Meetings
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-787
7.8
2020-11-06 CVE-2020-3603 Out-of-bounds Write vulnerability in Cisco Webex Meetings and Webex Meetings Server
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-787
7.8
2020-11-06 CVE-2020-3600 Incorrect Authorization vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-863
7.8
2020-11-06 CVE-2020-3595 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system.
local
low complexity
cisco CWE-732
7.8
2020-11-06 CVE-2020-3594 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-3593 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-3592 Incorrect Authorization vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system.
network
low complexity
cisco CWE-863
6.5
2020-11-06 CVE-2020-3591 Cross-site Scripting vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
4.3
2020-11-06 CVE-2020-3590 Cross-site Scripting vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user.
network
low complexity
cisco CWE-79
6.4
2020-11-06 CVE-2020-3588 Path Traversal vulnerability in Cisco Webex Meetings
A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system.
local
low complexity
cisco CWE-22
7.8