Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-20072 Unspecified vulnerability in Cisco IOS XE 17.9.1/17.9.1A/17.9.1W
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2023-03-23 CVE-2023-20080 Improper Validation of Array Index vulnerability in Cisco IOS and IOS XE
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.
network
low complexity
cisco CWE-129
7.5
2023-03-23 CVE-2023-20081 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
high complexity
cisco CWE-787
5.9
2023-03-23 CVE-2023-20082 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.
low complexity
cisco
6.8
2023-03-23 CVE-2023-20097 Command Injection vulnerability in Cisco products
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges.
local
low complexity
cisco CWE-77
6.7
2023-03-23 CVE-2023-20100 Unspecified vulnerability in Cisco IOS XE 17.10.1
A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
high complexity
cisco
6.8
2023-03-23 CVE-2023-20107 Insufficient Entropy vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the deterministic random bit generator (DRBG), also known as pseudorandom number generator (PRNG), in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco ASA 5506-X, ASA 5508-X, and ASA 5516-X Firewalls could allow an unauthenticated, remote attacker to cause a cryptographic collision, enabling the attacker to discover the private key of an affected device.
network
low complexity
cisco CWE-331
7.5
2023-03-23 CVE-2023-20112 Out-of-bounds Read vulnerability in Cisco products
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-125
6.5
2023-03-23 CVE-2023-20113 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Sd-Wan
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.1
2023-03-10 CVE-2022-20929 Improper Verification of Cryptographic Signature vulnerability in Cisco Enterprise NFV Infrastructure Software
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files.
local
low complexity
cisco CWE-347
7.8