Vulnerabilities > Cisco > Low

DATE CVE VULNERABILITY TITLE RISK
2020-06-18 CVE-2020-3355 Cross-site Scripting vulnerability in Cisco Data Center Network Manager
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
cisco CWE-79
3.5
2020-06-03 CVE-2020-3206 Improper Input Validation vulnerability in Cisco IOS XE 16.10.1/16.10.1E/16.10.1S
A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device.
low complexity
cisco CWE-20
3.3
2020-06-03 CVE-2020-3222 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device.
low complexity
cisco
3.3
2020-06-03 CVE-2020-3231 Incorrect Authorization vulnerability in Cisco IOS
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could allow an unauthenticated, adjacent attacker to forward broadcast traffic before being authenticated on the port.
2.9
2020-06-03 CVE-2020-3233 Cross-site Scripting vulnerability in Cisco IOX
A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based Local Manager interface of an affected device.
network
cisco CWE-79
3.5
2020-06-03 CVE-2020-3335 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device.
local
low complexity
cisco CWE-863
2.1
2020-05-22 CVE-2020-3343 Classic Buffer Overflow vulnerability in Cisco Advanced Malware Protection FOR Endpoints
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device.
local
low complexity
cisco CWE-120
2.1
2020-05-22 CVE-2020-3344 Classic Buffer Overflow vulnerability in Cisco Advanced Malware Protection FOR Endpoints
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device.
local
low complexity
cisco CWE-120
2.1
2020-05-06 CVE-2020-3301 Use of Hard-coded Credentials vulnerability in Cisco Firepower Management Center
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account.
local
low complexity
cisco CWE-798
2.1
2020-04-15 CVE-2020-3260 Resource Exhaustion vulnerability in Cisco products
A vulnerability in Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-400
3.3