Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-20265 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
low complexity
cisco CWE-79
5.4
2023-11-21 CVE-2023-20272 Unspecified vulnerability in Cisco Identity Services Engine 3.0.0/3.1
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application.
network
low complexity
cisco
8.8
2023-11-21 CVE-2023-20274 Unspecified vulnerability in Cisco Appdynamics
A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient permissions that are set by the PHP Agent Installer on the PHP Agent install directory.
local
low complexity
cisco
7.8
2023-11-01 CVE-2023-20031 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart.
network
high complexity
cisco
5.4
2023-11-01 CVE-2023-20042 Unspecified vulnerability in Cisco products
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
8.6
2023-11-01 CVE-2023-20048 Incorrect Authorization vulnerability in Cisco Firepower Management Center
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.
network
low complexity
cisco CWE-863
critical
9.9
2023-11-01 CVE-2023-20063 Improper Input Validation vulnerability in Cisco products
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary commands with root permissions on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input.
local
low complexity
cisco CWE-20
8.2
2023-11-01 CVE-2023-20070 Unspecified vulnerability in Cisco Firepower Threat Defense 7.2.0/7.2.0.1
A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart.
network
high complexity
cisco
4.0
2023-11-01 CVE-2023-20071 Unspecified vulnerability in Cisco products
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
network
low complexity
cisco
5.8
2023-11-01 CVE-2023-20083 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in ICMPv6 inspection when configured with the Snort 2 detection engine for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the CPU of an affected device to spike to 100 percent, which could stop all traffic processing and result in a denial of service (DoS) condition.
network
low complexity
cisco
8.6