Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-08-25 CVE-2021-1583 Unspecified vulnerability in Cisco Nx-Os 14.2(7F)
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system.
local
low complexity
cisco
4.4
2021-08-25 CVE-2021-1584 OS Command Injection vulnerability in Cisco Nx-Os 14.2(7F)
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2021-08-25 CVE-2021-1590 Unspecified vulnerability in Cisco Nx-Os and Unified Computing System
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition.
network
low complexity
cisco
5.3
2021-08-25 CVE-2021-1591 Unspecified vulnerability in Cisco Nx-Os 9.3(4)
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device.
network
low complexity
cisco
5.3
2021-08-25 CVE-2021-1592 Allocation of Resources Without Limits or Throttling vulnerability in Cisco Unified Computing System
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-770
4.3
2021-08-18 CVE-2021-1561 Improper Authentication vulnerability in Cisco Secure Email and web Manager
A vulnerability in the spam quarantine feature of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), could allow an authenticated, remote attacker to gain unauthorized access and modify the spam quarantine settings of another user.
network
low complexity
cisco CWE-287
5.4
2021-08-18 CVE-2021-34734 Double Free vulnerability in Cisco Video Surveillance 7000 IP Camera Firmware 2.12.4
A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for the Cisco Video Surveillance 7000 Series IP Cameras firmware could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
low complexity
cisco CWE-415
6.5
2021-08-04 CVE-2021-1522 Weak Password Requirements vulnerability in Cisco Connected Mobile Experiences
A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on an affected device.
network
low complexity
cisco CWE-521
4.3
2021-08-04 CVE-2021-34707 Information Exposure vulnerability in Cisco Evolved Programmable Network Manager
A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system.
network
low complexity
cisco CWE-200
6.5
2021-07-22 CVE-2021-33478 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proximate attacker to achieve arbitrary code execution in the TrustZone Trusted Execution Environment (TEE) of an affected device.
low complexity
cisco CWE-119
6.8