Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-34770 Out-of-bounds Write vulnerability in Cisco IOS XE
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-787
7.2
2021-09-09 CVE-2021-34708 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XR
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.
local
low complexity
cisco CWE-347
6.7
2021-09-09 CVE-2021-34709 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XR
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.
local
high complexity
cisco CWE-347
6.4
2021-09-09 CVE-2021-34713 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the Layer 2 punt code of Cisco IOS XR Software running on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to cause the affected line card to reboot.
low complexity
cisco
7.4
2021-09-09 CVE-2021-34718 Argument Injection or Modification vulnerability in Cisco IOS XR
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device.
network
low complexity
cisco CWE-88
8.1
2021-09-09 CVE-2021-34719 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
7.8
2021-09-09 CVE-2021-34720 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause device packet memory to become exhausted or cause the IP SLA process to crash, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2021-09-09 CVE-2021-34721 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34722 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34728 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
7.8