Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-24 CVE-2020-3141 Unspecified vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device.
network
low complexity
cisco
8.8
2020-09-24 CVE-2020-3559 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-400
8.6
2020-09-24 CVE-2020-3508 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition.
low complexity
cisco CWE-400
7.4
2020-09-24 CVE-2020-3396 Improper Privilege Management vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.
low complexity
cisco CWE-269
7.2
2020-09-23 CVE-2019-15283 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-119
7.8
2020-09-23 CVE-2019-15285 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-119
7.8
2020-09-23 CVE-2019-15287 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
local
low complexity
cisco CWE-119
7.8
2020-09-23 CVE-2019-15289 Improper Input Validation vulnerability in Cisco Roomos and Telepresence Collaboration Endpoint
Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-20
7.5
2020-09-23 CVE-2019-16007 Insufficient Verification of Data Authenticity vulnerability in Cisco Anyconnect Secure Mobility Client
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition.
local
low complexity
cisco CWE-345
7.1
2020-09-23 CVE-2019-16009 Cross-Site Request Forgery (CSRF) vulnerability in Cisco IOS
A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.8