Vulnerabilities > Cisco > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-22 CVE-2023-20240 Out-of-bounds Read vulnerability in Cisco Anyconnect Secure Mobility Client and Secure Client
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system.
local
low complexity
cisco CWE-125
5.5
2023-11-22 CVE-2023-20241 Out-of-bounds Read vulnerability in Cisco Anyconnect Secure Mobility Client and Secure Client
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software.
local
low complexity
cisco CWE-125
5.5
2023-11-21 CVE-2023-20208 Cross-site Scripting vulnerability in Cisco Identity Services Engine 3.0.0/3.1/3.2
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
4.8
2023-11-21 CVE-2023-20265 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based management interface of a small subset of Cisco IP Phones could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.
network
low complexity
cisco CWE-79
5.4
2023-11-01 CVE-2023-20031 Unspecified vulnerability in Cisco Firepower Threat Defense
A vulnerability in the SSL/TLS certificate handling of Snort 3 Detection Engine integration with Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart.
network
high complexity
cisco
5.4
2023-11-01 CVE-2023-20070 Unspecified vulnerability in Cisco Firepower Threat Defense 7.2.0/7.2.0.1
A vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to unexpectedly restart.
network
high complexity
cisco
4.0
2023-11-01 CVE-2023-20071 Unspecified vulnerability in Cisco products
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
network
low complexity
cisco
5.8
2023-11-01 CVE-2023-20170 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-11-01 CVE-2023-20246 Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system.
network
low complexity
snort cisco
5.3
2023-11-01 CVE-2023-20247 Unspecified vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to bypass a configured multiple certificate authentication policy and connect using only a valid username and password.
network
low complexity
cisco
4.3