Tagged “cisco”
CVEs tagged cisco, newest first.
181 CVEsRSS
CVE-2022-20811Medium· 5.5Cisco TelePresence Collaboration Endpoint and RoomOS Software Path Traversal Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20776Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Path Traversal Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20931Medium· 6.5Cisco Touch 10 Device Downgrade Attack Vulnerability
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability …
CVE-2022-20793Medium· 6.8Cisco Touch 10 Device Insufficient Identity Verification Vulnerability
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. Thi…
CVE-2022-20728Medium· 4.7Cisco Aironet Access Points VLAN bypass from Native VLAN Vulnerability
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This v…
CVE-2022-20768Medium· 4.9Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability (CVE-2022-20768)
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnera…
CVE-2022-20794Medium· 4.7vuln-CVE-2022-20794
Multiple vulnerabilities in the web engine of Cisco Telepresence CE Software and RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, redirect users to an attacker controlled destination or view sensi…
CVE-2022-20764Medium· 6.5Cisco RoomsOS Denial of Service Vulnerability
Multiple vulnerabilities in the web engine of Cisco Telepresence CE Software and RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, redirect users to an attacker controlled destination or view sensi…
CVE-2022-20783High· 7.5Cisco Telepresence CE and RoomOS Software Denial of Service Vulnerability
A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an …
CVE-2022-20622High· 8.6Cisco Aironet Access Points ICMP Denial of Service Vulnerability
A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of …
CVE-2021-1529High· 7.8Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2021-1529)
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An …
CVE-2021-34758NoneCisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability
It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment,…
CVE-2021-34725Medium· 6.7Cisco IOS XE SD-WAN Command Injection Vulnerability
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due…
CVE-2021-1625Medium· 5.8Cisco IOS XE Software Zone Based Firewall ICMP and UDP Inspection Vulnerability
A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists b…
CVE-2021-1619Critical· 9.8Cisco IOS XE Software NETCONF/RESTCONF AAA Vulnerability
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: In…
CVE-2021-34727Critical· 9.8Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability (CVE-2021-34727)
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an a…
CVE-2021-1612Medium· 5.5Cisco IOS XE SD-WAN Arbitrary File Overwrite Vulnerability
A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file …
CVE-2021-34740High· 7.4Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability (CVE-2021-34740)
A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS…
CVE-2021-1419High· 7.8Cisco Aironet Access Points Privilege Escalation Vulnerability
A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is du…
CVE-2021-1532Medium· 6.5Cisco Telepresence CE and RoomOS Software Arbitrary File Read Vulnerability
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating syste…
CVE-2021-1371Medium· 6.6Cisco SD-WAN Software Improper Privilege Management Vulnerability
A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the…
CVE-2021-1449Medium· 6.7Cisco Aironet Access Points Privilege Escalation Vulnerability
A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code th…
CVE-2021-1437High· 7.5Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to a…
CVE-2021-1273High· 7.5Cisco SD-WAN Denial of Service Vulnerabilties
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […
CVE-2021-1279Medium· 5.3Cisco SD-WAN Denial of Service Vulnerabilties
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […
CVE-2021-1278Medium· 5.5Cisco SD-WAN Denial of Service Vulnerabilties
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […
CVE-2021-1274High· 7.5Cisco SD-WAN Denial of Service Vulnerabilties
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […
CVE-2021-1241High· 8.6Cisco SD-WAN vEdge Routers Denial of Service Vulnerability
Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […
CVE-2020-26068Medium· 5.5Cisco Telepresence CE Software and RoomOS Software Unauthorized Configuration Change Vulnerability
A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient a…
CVE-2020-26086Medium· 4.3Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability (CVE-2020-26086)
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability i…