Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2022-20761 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device.
low complexity
cisco CWE-20
6.5
2022-04-06 CVE-2022-20665 Command Injection vulnerability in Cisco Staros
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-77
6.7
2022-04-06 CVE-2022-20675 Unspecified vulnerability in Cisco Asyncos
A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple Network Management Protocol (SNMP) service, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
5.3
2022-04-06 CVE-2022-20741 Cross-site Scripting vulnerability in Cisco Secure Network Analytics
A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
5.4
2022-04-06 CVE-2022-20754 Unspecified vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user.
network
low complexity
cisco
7.2
2022-04-06 CVE-2022-20755 Unspecified vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user.
network
low complexity
cisco
7.2
2022-04-06 CVE-2022-20756 Unspecified vulnerability in Cisco Identity Services Engine
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets.
network
low complexity
cisco
7.5
2022-04-06 CVE-2022-20762 Unspecified vulnerability in Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure 2020.02.2.0/2020.02.7.0
A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device.
local
low complexity
cisco
7.8
2022-04-06 CVE-2022-20763 Deserialization of Untrusted Data vulnerability in Cisco Webex Meetings Online Wbs42.2.11
A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attacker to inject arbitrary Java code.
network
low complexity
cisco CWE-502
8.8
2022-04-06 CVE-2022-20774 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web-based interface of an affected system.
network
low complexity
cisco CWE-352
8.1