Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-11-04 CVE-2021-40119 Use of Hard-coded Credentials vulnerability in Cisco Policy Suite
A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user.
network
low complexity
cisco CWE-798
critical
9.8
2021-09-23 CVE-2021-1619 Use of Uninitialized Resource vulnerability in Cisco products
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denial of service (DoS) on an affected device This vulnerability is due to an uninitialized variable.
network
low complexity
cisco CWE-908
critical
9.1
2021-09-23 CVE-2021-34727 Classic Buffer Overflow vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device.
network
low complexity
cisco CWE-120
critical
9.8
2021-09-02 CVE-2021-34746 Improper Authentication vulnerability in Cisco Enterprise NFV Infrastructure Software
A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and log in to an affected device as an administrator.
network
low complexity
cisco CWE-287
critical
9.8
2021-08-25 CVE-2021-1577 Unspecified vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an affected system.
network
low complexity
cisco
critical
9.1
2021-08-25 CVE-2021-1581 Unspecified vulnerability in Cisco products
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system.
network
low complexity
cisco
critical
9.1
2021-08-18 CVE-2021-34730 Out-of-bounds Write vulnerability in Cisco products
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
critical
9.8
2021-08-04 CVE-2021-1602 OS Command Injection vulnerability in Cisco Small Business RV Series Router Firmware 1.0.0.30/1.0.0.33/1.0.1.3
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
critical
9.8
2021-08-04 CVE-2021-1609 Unspecified vulnerability in Cisco Small Business RV Series Router Firmware
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) condition Execute arbitrary commands For more information about these vulnerabilities, see the Details section of this advisory.
network
low complexity
cisco
critical
9.8
2021-05-06 CVE-2021-1468 Improper Authentication vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application.
network
low complexity
cisco CWE-287
critical
9.8