Tagged “cisco”
CVEs tagged cisco, newest first.
181 CVEsRSS
CVE-2025-20317High· 7.1Cisco UCS Virtual Keyboard Video Monitor (vKVM) Open Redirect Vulnerability
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerabili…
CVE-2025-20278Medium· 6.0Cisco Unified Communications Products Command Injection Vulnerability (CVE-2025-20278)
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vuln…
CVE-2025-20129Medium· 4.3Cisco Customer Collaboration Platform Information Disclosure Vulnerability (CVE-2025-20129)
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability…
CVE-2025-20112Medium· 5.1Cisco Unified Communications Products Privilege Escalation Vulnerability (CVE-2025-20112)
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive perm…
CVE-2025-20151Medium· 4.3Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP,…
CVE-2024-20260High· 8.6Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found tha…
CVE-2024-20343Medium· 5.5Cisco IOS XR Software CLI Arbitrary File Read Vulnerability (CVE-2024-20343)
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device.…
CVE-2024-20317High· 7.4Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dr…
CVE-2024-20373Medium· 5.3Cisco IOS and Cisco IOS XE SNMP Extended ACL Bypass Vulnerability
A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP p…
CVE-2024-20271High· 8.6Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…
CVE-2024-20265Medium· 5.9Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…
CVE-2024-20267High· 8.6Cisco NX-OS Software MPLS IPv6 Denial of Serice Vulnerability
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traff…
CVE-2023-20268Medium· 4.7Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…
CVE-2023-20176Medium· 5.8Cisco Aironet Access Points Denial of Service
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…
CVE-2023-20033High· 8.6Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Switches Denial of Service Vulnerability
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c…
CVE-2023-20094Medium· 4.3Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20093Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20092Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20091Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20090Medium· 6.7Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20004Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20035High· 7.8Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2023-20035)
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI…
CVE-2023-20056Medium· 6.5Cisco Access Point Software Denial of Service
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input v…
CVE-2023-20112High· 7.4Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain pa…
CVE-2023-20097Medium· 4.6Cisco Access Points (AP) Command Injection Vulnerability
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands tha…
CVE-2023-20002Medium· 4.4Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
CVE-2023-20008Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
CVE-2022-20955Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20954Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20953Medium· 5.0Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …