Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-20096 Cross-site Scripting vulnerability in Cisco Unified Contact Center Express
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack.
network
low complexity
cisco CWE-79
5.4
2023-04-05 CVE-2023-20102 Deserialization of Untrusted Data vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system.
network
low complexity
cisco CWE-502
8.8
2023-04-05 CVE-2023-20103 Improper Input Validation vulnerability in Cisco Secure Network Analytics 2.1.1/7.4.1
A vulnerability in Cisco Secure Network Analytics could allow an authenticated, remote attacker to execute arbitrary code as a root user on an affected device.
network
low complexity
cisco CWE-20
7.2
2023-04-05 CVE-2023-20117 OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
7.2
2023-04-05 CVE-2023-20121 OS Command Injection vulnerability in Cisco Identity Services Engine and Prime Infrastructure
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20122 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
local
low complexity
cisco CWE-78
7.8
2023-04-05 CVE-2023-20123 Authentication Bypass by Capture-replay vulnerability in Cisco DUO and DUO Authentication for Windows Logon and RDP
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device.
low complexity
cisco CWE-294
4.6
2023-04-05 CVE-2023-20137 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20138 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20139 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1