Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-20223 Unspecified vulnerability in Cisco DNA Center
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on API requests.
network
low complexity
cisco
8.2
2023-09-27 CVE-2023-20226 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20227 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20231 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation.
network
low complexity
cisco CWE-20
8.8
2023-09-27 CVE-2023-20251 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Mobility Express Software
A vulnerability in the memory buffer of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause memory leaks that could eventually lead to a device reboot. This vulnerability is due to memory leaks caused by multiple clients connecting under specific conditions.
high complexity
cisco CWE-119
5.3
2023-09-27 CVE-2023-20252 Improper Authentication vulnerability in Cisco Catalyst Sd-Wan Manager 20.11.1.2/20.9.3.2
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs.
network
low complexity
cisco CWE-287
critical
9.8
2023-09-27 CVE-2023-20253 Unspecified vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the command line interface (cli) management interface of Cisco SD-WAN vManage could allow an authenticated, local attacker to bypass authorization and allow the attacker to roll back the configuration on vManage controllers and edge router device. This vulnerability is due to improper access control in the cli-management interface of an affected system.
local
low complexity
cisco
5.5
2023-09-27 CVE-2023-20254 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan Manager
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance.
network
low complexity
cisco CWE-732
8.8
2023-09-27 CVE-2023-20262 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20268 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient management of resources when handling certain types of traffic.
low complexity
cisco CWE-400
4.7