Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2022-11-04 CVE-2022-20937 Resource Exhaustion vulnerability in Cisco Identity Services Engine
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources.
network
low complexity
cisco CWE-400
5.3
2022-11-04 CVE-2022-20942 Incorrect Authorization vulnerability in Cisco Asyncos
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks.
network
low complexity
cisco CWE-863
6.5
2022-11-04 CVE-2022-20951 Server-Side Request Forgery (SSRF) vulnerability in Cisco Broadworks Messaging Server 22.0
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-918
6.5
2022-11-04 CVE-2022-20956 Unspecified vulnerability in Cisco Identity Services Engine 3.1/3.2
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device.
network
low complexity
cisco
8.8
2022-11-04 CVE-2022-20958 Server-Side Request Forgery (SSRF) vulnerability in Cisco Broadworks Commpilot Application
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-918
8.8
2022-11-04 CVE-2022-20960 Improper Certificate Validation vulnerability in Cisco Email Security Appliance
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device.
network
low complexity
cisco CWE-295
7.5
2022-11-04 CVE-2022-20961 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device.
network
low complexity
cisco CWE-352
8.8
2022-11-04 CVE-2022-20962 Path Traversal vulnerability in Cisco Identity Services Engine 3.1
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation.
network
low complexity
cisco CWE-22
8.8
2022-11-04 CVE-2022-20963 Cross-site Scripting vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
5.4
2022-11-04 CVE-2022-20969 Cross-site Scripting vulnerability in Cisco Umbrella 003.003(000)
A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized user input.
network
low complexity
cisco CWE-79
5.4