Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2022-09-30 CVE-2022-20818 Path Traversal vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges.
local
low complexity
cisco CWE-22
7.8
2022-09-30 CVE-2022-20844 Use of Hard-coded Credentials vulnerability in Cisco Sd-Wan
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password combination.
network
low complexity
cisco CWE-798
5.3
2022-09-30 CVE-2022-20847 Unspecified vulnerability in Cisco IOS XE 17.3.3
A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2022-09-30 CVE-2022-20848 Unspecified vulnerability in Cisco IOS XE 17.6.1/17.6.3/17.9.1
A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2022-09-30 CVE-2022-20850 Improper Input Validation vulnerability in Cisco products
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device.
local
low complexity
cisco CWE-20
7.1
2022-09-30 CVE-2022-20851 OS Command Injection vulnerability in Cisco IOS XE 17.6.1
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.
network
low complexity
cisco CWE-78
7.2
2022-09-30 CVE-2022-20855 OS Command Injection vulnerability in Cisco IOS XE 17.6.1
A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an authenticated, local attacker to escape the restricted controller shell and execute arbitrary commands on the underlying operating system of the access point.
local
low complexity
cisco CWE-78
6.7
2022-09-30 CVE-2022-20856 Unspecified vulnerability in Cisco IOS XE 17.3.4C
A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2022-09-30 CVE-2022-20919 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS XE 17.9.1
A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.5
2022-09-30 CVE-2022-20930 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system.
local
low complexity
cisco CWE-78
6.7