Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-34723 Exposure of Resource to Wrong Sphere vulnerability in Cisco IOS XE 17.3.1A
A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device.
local
low complexity
cisco CWE-668
6.7
2021-09-23 CVE-2021-34724 Unspecified vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user.
local
low complexity
cisco
6.0
2021-09-23 CVE-2021-34725 OS Command Injection vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34726 OS Command Injection vulnerability in Cisco Sd-Wan
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34727 Classic Buffer Overflow vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device.
network
low complexity
cisco CWE-120
critical
9.8
2021-09-23 CVE-2021-34729 OS Command Injection vulnerability in Cisco IOS XE and IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34740 Memory Leak vulnerability in Cisco Aironet Access Point Software 17.2/17.3
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition.
low complexity
cisco CWE-401
7.4
2021-09-23 CVE-2021-34767 Always-Incorrect Control Flow Implementation vulnerability in Cisco IOS XE
A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN.
low complexity
cisco CWE-670
7.4
2021-09-23 CVE-2021-34768 Double Free vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-415
7.5
2021-09-23 CVE-2021-34769 Double Free vulnerability in Cisco IOS XE
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-415
7.5