Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2024-01-17 CVE-2023-20258 Unspecified vulnerability in Cisco Prime Infrastructure
A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system.
network
low complexity
cisco
7.2
2024-01-17 CVE-2023-20260 Argument Injection or Modification vulnerability in Cisco Prime Infrastructure
A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated privileges.
local
low complexity
cisco CWE-88
6.7
2024-01-17 CVE-2023-20271 SQL Injection vulnerability in Cisco Prime Infrastructure
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
network
low complexity
cisco CWE-89
6.5
2024-01-17 CVE-2024-20251 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
low complexity
cisco CWE-79
5.4
2024-01-17 CVE-2024-20270 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input.
network
low complexity
cisco CWE-79
5.4
2024-01-17 CVE-2024-20272 Unspecified vulnerability in Cisco Unity Connection
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system.
network
low complexity
cisco
critical
9.8
2024-01-17 CVE-2024-20277 Unspecified vulnerability in Cisco Thousandeyes Enterprise Agent
A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.
network
low complexity
cisco
8.0
2024-01-17 CVE-2024-20287 Command Injection vulnerability in Cisco Wap371 Firmware
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-77
7.2
2024-01-10 CVE-2023-31488 Unspecified vulnerability in Cisco products
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
network
low complexity
cisco
critical
9.8
2023-12-12 CVE-2023-20275 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address.
network
low complexity
cisco
4.3