Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-04 CVE-2021-1602 OS Command Injection vulnerability in Cisco Small Business RV Series Router Firmware 1.0.0.30/1.0.0.33/1.0.1.3
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
critical
9.8
2021-05-06 CVE-2021-1498 OS Command Injection vulnerability in Cisco Hyperflex HX Data Platform
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-78
critical
9.8
2021-05-06 CVE-2021-1497 OS Command Injection vulnerability in Cisco Hyperflex HX Data Platform 4.0(2A)
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-78
critical
9.8
2021-05-06 CVE-2021-1468 Improper Authentication vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application.
network
low complexity
cisco CWE-287
critical
9.8
2021-04-08 CVE-2021-1459 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-20
critical
9.8
2021-04-08 CVE-2021-1472 Improper Authentication vulnerability in Cisco products
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers.
network
low complexity
cisco CWE-287
critical
9.8
2021-04-08 CVE-2021-1473 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers.
network
low complexity
cisco CWE-78
critical
9.8
2021-04-08 CVE-2021-1479 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system.
network
low complexity
cisco CWE-119
critical
9.8
2021-03-24 CVE-2021-1411 Improper Null Termination vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-170
critical
9.9
2021-03-24 CVE-2021-1435 Path Traversal vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user.
network
low complexity
cisco CWE-22
critical
9.0