Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2021-1130 Cross-site Scripting vulnerability in Cisco DNA Center
A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.
network
low complexity
cisco CWE-79
4.8
2021-01-13 CVE-2021-1127 Cross-site Scripting vulnerability in Cisco Enterprise NFV Infrastructure Software
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
5.4
2020-11-18 CVE-2020-3482 Improper Privilege Management vulnerability in Cisco products
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations.
network
low complexity
cisco CWE-269
6.4
2020-11-18 CVE-2020-3471 Improper Synchronization vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to maintain bidirectional audio despite being expelled from an active Webex session.
network
low complexity
cisco CWE-662
6.5
2020-11-18 CVE-2020-3441 Unspecified vulnerability in Cisco Webex Meetings Server
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to view sensitive information from the meeting room lobby.
network
low complexity
cisco
5.3
2020-11-18 CVE-2020-3392 Missing Authentication for Critical Function vulnerability in Cisco IOT Field Network Director
A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system.
network
low complexity
cisco CWE-306
5.0
2020-11-18 CVE-2020-27126 Cross-site Scripting vulnerability in Cisco Webex Meetings 40.10.2
A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
network
low complexity
cisco CWE-79
6.1
2020-11-18 CVE-2020-26081 Injection vulnerability in Cisco IOT Field Network Director
Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system.
network
cisco CWE-74
4.3
2020-11-18 CVE-2020-26080 Improper Privilege Management vulnerability in Cisco IOT Field Network Director
A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system.
network
low complexity
cisco CWE-269
4.0
2020-11-18 CVE-2020-26079 Insufficiently Protected Credentials vulnerability in Cisco IOT Field Network Director
A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device.
network
low complexity
cisco CWE-522
4.0