Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-1371 Improper Privilege Management vulnerability in Cisco IOS XE Sd-Wan 17.2.0
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the default SD-WAN configuration.
low complexity
cisco CWE-269
6.6
2021-03-24 CVE-2021-1356 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-755
4.3
2021-03-24 CVE-2021-1352 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE
A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
low complexity
cisco CWE-119
6.5
2021-03-24 CVE-2021-1281 Unspecified vulnerability in Cisco IOS XE
A vulnerability in CLI management in Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system as the root user.
local
low complexity
cisco
6.7
2021-03-24 CVE-2021-1220 Unspecified vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
4.3
2021-03-24 CVE-2021-1471 Improper Certificate Validation vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition.
network
high complexity
cisco CWE-295
5.6
2021-03-24 CVE-2021-1454 Argument Injection or Modification vulnerability in Cisco IOS XE and IOS XE Sd-Wan
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges.
local
low complexity
cisco CWE-88
6.7
2021-03-24 CVE-2021-1453 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XE
A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time.
low complexity
cisco CWE-347
6.8
2021-03-24 CVE-2021-1452 OS Command Injection vulnerability in Cisco IOS XE ROM Monitor
A vulnerability in the ROM Monitor (ROMMON) of Cisco IOS XE Software for Cisco Catalyst IE3200, IE3300, and IE3400 Rugged Series Switches, Cisco Catalyst IE3400 Heavy Duty Series Switches, and Cisco Embedded Services 3300 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time.
low complexity
cisco CWE-78
6.8
2021-03-24 CVE-2021-1449 Unspecified vulnerability in Cisco products
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time.
local
low complexity
cisco
6.7