Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-20029 Unspecified vulnerability in Cisco IOS XE 17.7.1/17.8.1
A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20035 Unspecified vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20055 Unspecified vulnerability in Cisco DNA Center
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device.
network
low complexity
cisco
8.8
2023-03-23 CVE-2023-20056 Unspecified vulnerability in Cisco products
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.
local
low complexity
cisco
5.5
2023-03-23 CVE-2023-20059 Cleartext Storage of Sensitive Information vulnerability in Cisco DNA Center
A vulnerability in the implementation of the Cisco Network Plug-and-Play (PnP) agent of Cisco DNA Center could allow an authenticated, remote attacker to view sensitive information in clear text.
network
low complexity
cisco CWE-312
6.5
2023-03-23 CVE-2023-20065 Unspecified vulnerability in Cisco IOS XE 17.11.1/17.6.3
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20066 Path Traversal vulnerability in Cisco IOS XE 16.12.3/17.3.2/17.6.2
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI.
network
low complexity
cisco CWE-22
6.5
2023-03-23 CVE-2023-20067 Allocation of Resources Without Limits or Throttling vulnerability in Cisco IOS XE
A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-770
6.5
2023-03-23 CVE-2023-20072 Unspecified vulnerability in Cisco IOS XE 17.9.1/17.9.1A/17.9.1W
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2023-03-23 CVE-2023-20080 Improper Validation of Array Index vulnerability in Cisco IOS and IOS XE
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.
network
low complexity
cisco CWE-129
7.5