Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-20033 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when processing traffic that is received on the management interface.
network
low complexity
cisco
8.6
2023-09-27 CVE-2023-20034 Unspecified vulnerability in Cisco Sd-Wan
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20176 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources.
network
low complexity
cisco CWE-400
8.6
2023-09-27 CVE-2023-20187 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20223 Unspecified vulnerability in Cisco DNA Center
A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on API requests.
network
low complexity
cisco
8.2
2023-09-27 CVE-2023-20226 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20227 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets.
network
low complexity
cisco
7.5
2023-09-27 CVE-2023-20231 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation.
network
low complexity
cisco CWE-20
8.8
2023-09-27 CVE-2023-20254 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan Manager
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance.
network
low complexity
cisco CWE-732
8.8
2023-09-27 CVE-2023-20262 Unspecified vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the SSH service of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to cause a process crash, resulting in a DoS condition for SSH access only.
network
low complexity
cisco
7.5