Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-1564 Memory Leak vulnerability in Cisco products
Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-401
6.5
2021-05-22 CVE-2021-1254 Unspecified vulnerability in Cisco Finesse
Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
cisco
4.8
2021-05-22 CVE-2021-1358 Unspecified vulnerability in Cisco Finesse
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page.
network
low complexity
cisco
6.1
2021-05-22 CVE-2021-1557 Unspecified vulnerability in Cisco DNA Spaces: Connector
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.
local
low complexity
cisco
6.7
2021-05-22 CVE-2021-1558 Unspecified vulnerability in Cisco DNA Spaces: Connector
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.
local
low complexity
cisco
6.7
2021-05-11 CVE-2020-26139 Improper Authentication vulnerability in multiple products
An issue was discovered in the kernel in NetBSD 7.1.
5.3
2021-05-11 CVE-2020-26140 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H.
6.5
2021-05-11 CVE-2020-26141 Improper Validation of Integrity Check Value vulnerability in multiple products
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H.
low complexity
alfa cisco siemens CWE-354
6.5
2021-05-06 CVE-2021-1397 Unspecified vulnerability in Cisco products
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
network
low complexity
cisco
6.1
2021-05-06 CVE-2021-1438 Unspecified vulnerability in Cisco Wide Area Application Services
A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device.
local
low complexity
cisco
5.5