Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2020-10-21 CVE-2020-3373 Memory Leak vulnerability in Cisco products
A vulnerability in the IP fragment-handling implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a memory leak on an affected device.
network
low complexity
cisco CWE-401
8.6
2020-10-21 CVE-2020-3317 Improper Input Validation vulnerability in Cisco Firepower Threat Defense
A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances.
network
low complexity
cisco CWE-20
7.5
2020-10-21 CVE-2020-3304 Improper Input Validation vulnerability in Cisco products
A vulnerability in the web interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2020-10-14 CVE-2020-3427 Unspecified vulnerability in Cisco DUO Authentication for Windows Logon and RDP
The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths.
local
low complexity
cisco
7.8
2020-10-08 CVE-2020-3596 Always-Incorrect Control Flow Implementation vulnerability in Cisco products
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-670
7.5
2020-10-08 CVE-2020-3544 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute arbitrary code on an affected device or cause the device to reload.
low complexity
cisco CWE-119
8.8
2020-10-08 CVE-2020-3535 Uncontrolled Search Path Element vulnerability in Cisco Webex Teams
A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to load a malicious library.
local
low complexity
cisco CWE-427
8.4
2020-10-08 CVE-2020-3467 Incorrect Authorization vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.
network
low complexity
cisco CWE-863
7.7
2020-09-24 CVE-2020-3560 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affected device.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3552 NULL Pointer Dereference vulnerability in Cisco products
A vulnerability in the Ethernet packet handling of Cisco Aironet Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-476
7.4