Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-20184 Files or Directories Accessible to External Parties vulnerability in Cisco DNA Center
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user.
network
low complexity
cisco CWE-552
4.3
2023-05-09 CVE-2023-20098 Path Traversal vulnerability in Cisco Sd-Wan Vmanage
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system commands.
local
low complexity
cisco CWE-22
6.0
2023-04-05 CVE-2023-20096 Cross-site Scripting vulnerability in Cisco Unified Contact Center Express
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack.
network
low complexity
cisco CWE-79
5.4
2023-04-05 CVE-2023-20121 OS Command Injection vulnerability in Cisco Identity Services Engine and Prime Infrastructure
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20123 Authentication Bypass by Capture-replay vulnerability in Cisco DUO and DUO Authentication for Windows Logon and RDP
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and Duo Authentication for Windows Logon and RDP could allow an unauthenticated, physical attacker to replay valid user session credentials and gain unauthorized access to an affected macOS or Windows device.
low complexity
cisco CWE-294
4.6
2023-04-05 CVE-2023-20137 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20138 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20139 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20140 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1
2023-04-05 CVE-2023-20141 Cross-site Scripting vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
network
low complexity
cisco CWE-79
6.1