Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-06 CVE-2020-3604 Out-of-bounds Write vulnerability in Cisco Webex Meetings
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-787
7.8
2020-11-06 CVE-2020-3603 Out-of-bounds Write vulnerability in Cisco Webex Meetings and Webex Meetings Server
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-787
7.8
2020-11-06 CVE-2020-3600 Incorrect Authorization vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-863
7.8
2020-11-06 CVE-2020-3595 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating system.
local
low complexity
cisco CWE-732
7.8
2020-11-06 CVE-2020-3594 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-3593 Improper Privilege Management vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-269
7.8
2020-11-06 CVE-2020-3588 Path Traversal vulnerability in Cisco Webex Meetings
A vulnerability in virtualization channel messaging in Cisco Webex Meetings Desktop App for Windows could allow a local attacker to execute arbitrary code on a targeted system.
local
low complexity
cisco CWE-22
7.8
2020-11-06 CVE-2020-3574 Unspecified vulnerability in Cisco products
A vulnerability in the TCP packet processing functionality of Cisco IP Phones could allow an unauthenticated, remote attacker to cause the phone to stop responding to incoming calls, drop connected calls, or unexpectedly reload.
network
low complexity
cisco
7.5
2020-11-06 CVE-2020-3573 Improper Initialization vulnerability in Cisco Webex Meetings and Webex Meetings Server
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-665
7.8
2020-11-06 CVE-2020-3556 Unspecified vulnerability in Cisco Anyconnect Secure Mobility Client 4.9(3052)/98.145(86)
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script.
local
low complexity
cisco
7.3