Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2021-01-20 CVE-2021-1261 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device.
local
low complexity
cisco CWE-77
7.8
2021-01-20 CVE-2021-1260 Command Injection vulnerability in Cisco products
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device.
local
low complexity
cisco CWE-77
7.8
2021-01-20 CVE-2021-1257 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent.
network
low complexity
cisco mcafee CWE-352
8.8
2021-01-20 CVE-2021-1133 Incomplete Blacklist vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.
network
low complexity
cisco CWE-184
7.3
2021-01-13 CVE-2021-1360 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly.
network
low complexity
cisco CWE-787
7.2
2021-01-13 CVE-2021-1307 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly.
network
low complexity
cisco CWE-787
7.2
2021-01-13 CVE-2021-1240 Uncontrolled Search Path Element vulnerability in Cisco Proximity
A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a malicious library.
local
low complexity
cisco CWE-427
7.3
2021-01-13 CVE-2021-1237 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack.
local
low complexity
cisco CWE-427
7.8
2021-01-13 CVE-2021-1223 Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP.
network
low complexity
cisco snort
7.5
2021-01-13 CVE-2021-1217 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly.
network
low complexity
cisco CWE-787
7.2