Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-20117 OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
7.2
2023-04-05 CVE-2023-20122 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
local
low complexity
cisco CWE-78
7.8
2023-04-05 CVE-2023-20124 Command Injection vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
network
low complexity
cisco CWE-77
7.2
2023-04-05 CVE-2023-20128 OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
7.2
2023-04-05 CVE-2023-20051 Unspecified vulnerability in Cisco Packet Data Network Gateway 21.26.0/21.27.0
A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection.
network
low complexity
cisco
7.5
2023-03-23 CVE-2023-20027 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
8.6
2023-03-23 CVE-2023-20029 Unspecified vulnerability in Cisco IOS XE 17.7.1/17.8.1
A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20035 Unspecified vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges.
local
low complexity
cisco
7.8
2023-03-23 CVE-2023-20055 Unspecified vulnerability in Cisco DNA Center
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote attacker to elevate privileges in the context of the web-based management interface on an affected device.
network
low complexity
cisco
8.8
2023-03-23 CVE-2023-20065 Unspecified vulnerability in Cisco IOS XE 17.11.1/17.6.3
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
local
low complexity
cisco
7.8