Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2021-11-04 CVE-2021-40115 Cross-site Scripting vulnerability in Cisco Collaboration Meeting Rooms and Webex Video Mesh
A vulnerability in Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2021-11-04 CVE-2021-40119 Use of Hard-coded Credentials vulnerability in Cisco Policy Suite
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user.
network
low complexity
cisco CWE-798
critical
9.8
2021-11-04 CVE-2021-40120 OS Command Injection vulnerability in Cisco Application Extension Platform and IOS XR
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using root-level privileges.
network
low complexity
cisco CWE-78
7.2
2021-11-04 CVE-2021-40124 Improper Privilege Management vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device.
local
low complexity
cisco CWE-269
7.8
2021-11-04 CVE-2021-40126 Information Exposure Through an Error Message vulnerability in Cisco Umbrella
A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure.
network
low complexity
cisco CWE-209
4.3
2021-11-04 CVE-2021-40127 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an unauthenticated, remote attacker to render the web-based management interface unusable, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2021-11-04 CVE-2021-40128 Unspecified vulnerability in Cisco Webex Meetings
A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain.
network
low complexity
cisco
5.3
2021-10-27 CVE-2021-34754 Unspecified vulnerability in Cisco products
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured rules for ENIP traffic.
network
low complexity
cisco
7.5
2021-10-27 CVE-2021-34755 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
7.8
2021-10-27 CVE-2021-34756 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
7.8