Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-3371 OS Command Injection vulnerability in Cisco Integrated Management Controller 3.0(1C)
A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level.
network
low complexity
cisco CWE-78
8.8
2020-11-06 CVE-2020-27122 Improper Privilege Management vulnerability in Cisco Identity Services Engine
A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-269
7.2
2020-10-21 CVE-2020-3572 Memory Leak vulnerability in Cisco Firepower Threat Defense
A vulnerability in the SSL/TLS session handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-401
8.6
2020-10-21 CVE-2020-3571 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the ICMP ingress packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 4110 appliances could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.8
2020-10-21 CVE-2020-3563 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
A vulnerability in the packet processing functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
7.8
2020-10-21 CVE-2020-3562 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Firepower Threat Defense 6.3.0/6.4.0/6.5.0
A vulnerability in the SSL/TLS inspection of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series firewalls could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
cisco CWE-119
7.1
2020-10-21 CVE-2020-3555 Improper Resource Shutdown or Release vulnerability in Cisco Firepower Threat Defense
A vulnerability in the SIP inspection process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-404
7.5
2020-10-21 CVE-2020-3554 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the TCP packet processing of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-400
7.5
2020-10-21 CVE-2020-3533 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to restart unexpectedly.
network
low complexity
cisco CWE-400
7.5
2020-10-21 CVE-2020-3529 Resource Exhaustion vulnerability in Cisco products
A vulnerability in the SSL VPN negotiation process for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.5