Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2023-03-23 CVE-2023-20072 Unspecified vulnerability in Cisco IOS XE 17.9.1/17.9.1A/17.9.1W
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2023-03-23 CVE-2023-20080 Improper Validation of Array Index vulnerability in Cisco IOS and IOS XE
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition.
network
low complexity
cisco CWE-129
7.5
2023-03-23 CVE-2023-20113 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Sd-Wan
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.1
2023-03-10 CVE-2022-20929 Improper Verification of Cryptographic Signature vulnerability in Cisco Enterprise NFV Infrastructure Software
A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, local attacker to provide an unauthentic upgrade file for upload. This vulnerability is due to insufficient cryptographic signature verification of upgrade files.
local
low complexity
cisco CWE-347
7.8
2023-03-09 CVE-2023-20049 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XR
A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2023-03-03 CVE-2023-20079 Out-of-bounds Write vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-787
7.5
2023-03-03 CVE-2023-20088 Unspecified vulnerability in Cisco Finesse
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users who are connected through a load balancer.
network
low complexity
cisco
7.5
2023-03-01 CVE-2023-20009 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access.
network
low complexity
cisco CWE-434
7.2
2023-03-01 CVE-2023-20014 Resource Exhaustion vulnerability in Cisco Nexus Dashboard
A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests.
network
low complexity
cisco CWE-400
7.5
2023-02-23 CVE-2023-20011 Cross-Site Request Forgery (CSRF) vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.8