Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-20152 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20051 Unspecified vulnerability in Cisco Packet Data Network Gateway 21.26.0/21.27.0
A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection.
network
low complexity
cisco
7.5
2023-04-05 CVE-2023-20022 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20023 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20030 XXE vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself.
network
low complexity
cisco CWE-611
6.0
2023-04-05 CVE-2023-20073 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device.
network
low complexity
cisco CWE-434
critical
9.8
2023-04-05 CVE-2023-20021 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-03-23 CVE-2023-20027 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
8.6
2023-03-23 CVE-2023-20029 Unspecified vulnerability in Cisco IOS XE 17.7.1/17.8.1
A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20035 Unspecified vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges.
local
low complexity
cisco
7.8