Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-3349 Cross-site Scripting vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
cisco CWE-79
3.5
2020-07-16 CVE-2020-3348 Cross-site Scripting vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
cisco CWE-79
3.5
2020-07-16 CVE-2020-3345 Improper Input Validation vulnerability in Cisco Webex Meetings
A vulnerability in certain web pages of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to modify a web page in the context of a browser.
network
cisco CWE-20
4.3
2020-07-16 CVE-2020-3332 OS Command Injection vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device.
network
low complexity
cisco CWE-78
critical
9.0
2020-07-16 CVE-2020-3331 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-119
critical
10.0
2020-07-16 CVE-2020-3330 Use of Hard-coded Credentials vulnerability in Cisco Rv110W Wireless-N VPN Firewall Firmware
A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker to take full control of the device with a high-privileged account.
network
low complexity
cisco CWE-798
critical
10.0
2020-07-16 CVE-2020-3323 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-20
critical
10.0
2020-07-16 CVE-2020-3197 Improper Authentication vulnerability in Cisco Meeting Server
A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system.
network
low complexity
cisco CWE-287
5.0
2020-07-16 CVE-2020-3180 Insufficiently Protected Credentials vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, local attacker to access an affected device by using an account that has a default, static password.
local
low complexity
cisco CWE-522
7.8
2020-07-16 CVE-2020-3150 Incorrect Authorization vulnerability in Cisco Rv110W Firmware and Rv215W Firmware
A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which could include the device configuration.
network
cisco CWE-863
4.3