Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2020-10-21 CVE-2020-3528 Resource Exhaustion vulnerability in Cisco Firepower Threat Defense
A vulnerability in the OSPF Version 2 (OSPFv2) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-400
7.5
2020-10-21 CVE-2020-3499 Resource Exhaustion vulnerability in Cisco Firepower Management Center
A vulnerability in the licensing service of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.The vulnerability is due to improper handling of system resource values by the affected system.
network
low complexity
cisco CWE-400
8.6
2020-10-21 CVE-2020-3459 OS Command Injection vulnerability in Cisco Firepower Extensible Operating System
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
7.2
2020-10-21 CVE-2020-3456 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 2.4(1.249)
A vulnerability in the Cisco Firepower Chassis Manager (FCM) of Cisco FXOS Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected device.
network
low complexity
cisco CWE-352
8.8
2020-10-21 CVE-2020-3455 Unspecified vulnerability in Cisco Firepower Extensible Operating System
A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms.
local
low complexity
cisco
7.2
2020-10-21 CVE-2020-3436 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Firepower Threat Defense
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to upload arbitrary-sized files to specific folders on an affected device, which could lead to an unexpected device reload.
network
low complexity
cisco CWE-434
8.6
2020-10-21 CVE-2020-3410 Improper Authentication vulnerability in Cisco Firepower Management Center 6.6.0/6.6.0.1
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC system.
network
high complexity
cisco CWE-287
8.1
2020-10-21 CVE-2020-3373 Memory Leak vulnerability in Cisco products
A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device.
network
low complexity
cisco CWE-401
8.6
2020-10-21 CVE-2020-3304 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2020-10-08 CVE-2020-3596 Always-Incorrect Control Flow Implementation vulnerability in Cisco products
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-670
7.5