Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-09-24 CVE-2020-3393 Improper Input Validation vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
local
low complexity
cisco CWE-20
7.8
2020-09-24 CVE-2020-3390 Improper Input Validation vulnerability in Cisco IOS XE 16.12.1
A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-20
7.4
2020-09-24 CVE-2020-3359 Improper Input Validation vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2020-09-24 CVE-2020-3141 Unspecified vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device.
network
low complexity
cisco
8.8
2020-09-24 CVE-2020-3559 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3418 Unspecified vulnerability in Cisco IOS XE 17.1.1
A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send ICMPv6 traffic prior to the client being placed into RUN state.
low complexity
cisco
4.7
2020-09-24 CVE-2020-3508 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition.
low complexity
cisco CWE-400
7.4
2020-09-24 CVE-2020-3396 Improper Privilege Management vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.
low complexity
cisco CWE-269
7.2
2020-09-23 CVE-2019-15283 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-119
7.8
2020-09-23 CVE-2019-15285 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-119
7.8