Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2023-03-09 CVE-2023-20049 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XR
A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2023-03-09 CVE-2023-20064 Missing Authorization vulnerability in Cisco IOS XR
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line.
low complexity
cisco CWE-862
4.6
2023-03-03 CVE-2023-20061 Exposure of Resource to Wrong Sphere vulnerability in Cisco products
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system.
network
low complexity
cisco CWE-668
6.5
2023-03-03 CVE-2023-20062 Server-Side Request Forgery (SSRF) vulnerability in Cisco products
Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system.
network
low complexity
cisco CWE-918
4.3
2023-03-03 CVE-2023-20069 Cross-site Scripting vulnerability in Cisco Prime Infrastructure
A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
low complexity
cisco CWE-79
5.4
2023-03-03 CVE-2023-20078 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
critical
9.8
2023-03-03 CVE-2023-20079 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
7.5
2023-03-03 CVE-2023-20088 Unspecified vulnerability in Cisco Finesse
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer.
network
low complexity
cisco
7.5
2023-03-03 CVE-2023-20104 Cross-site Scripting vulnerability in Cisco Webex Teams
A vulnerability in the file upload functionality of Cisco Webex App for Web could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-03-01 CVE-2022-20952 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a network that should have been blocked. This vulnerability exists because malformed, encoded traffic is not properly detected.
network
low complexity
cisco
5.3