VulnSea

Tagged “vendor-advisory”

CVEs tagged vendor-advisory, newest first.

181 CVEsRSS

CVE-2025-20317High· 7.1
1y ago

Cisco UCS Virtual Keyboard Video Monitor (vKVM) Open Redirect Vulnerability

A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerabili…

▾ TwilightCisco · Cisco Unified Computing System (Managed)EPSS 0.43%via CSAF
CVE-2025-20278Medium· 6.0
1y ago

Cisco Unified Communications Products Command Injection Vulnerability (CVE-2025-20278)

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vuln…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.18%via CSAF
CVE-2025-20129Medium· 4.3
1y ago

Cisco Customer Collaboration Platform Information Disclosure Vulnerability (CVE-2025-20129)

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability…

▾ SunlitCisco · Cisco SocialMinerEPSS 0.34%via CSAF
CVE-2025-20112Medium· 5.1
1y ago

Cisco Unified Communications Products Privilege Escalation Vulnerability (CVE-2025-20112)

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive perm…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.14%via CSAF
CVE-2025-20151Medium· 4.3
1y ago

Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP,…

▾ SunlitCisco · IOSEPSS 0.39%via CSAF
CVE-2024-20260High· 8.6
1y ago

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found tha…

▾ TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.59%via NVD
CVE-2024-20343Medium· 5.5
2y ago

Cisco IOS XR Software CLI Arbitrary File Read Vulnerability (CVE-2024-20343)

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device.…

▾ SunlitCisco · Cisco IOS XR SoftwareEPSS 0.14%via CSAF
CVE-2024-20317High· 7.4
2y ago

Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dr…

▾ TwilightCisco · Cisco IOS XR SoftwareEPSS 0.24%via CSAF
CVE-2024-20373Medium· 5.3
2y ago

Cisco IOS and Cisco IOS XE SNMP Extended ACL Bypass Vulnerability

A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP p…

▾ SunlitCisco · IOSEPSS 0.50%via CSAF
CVE-2024-20271High· 8.6
2y ago

Cisco Access Point Software Denial of Service Vulnerability (CVE-2024-20271)

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficien…

▾ TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.63%via CSAF
CVE-2024-20265Medium· 5.9
2y ago

Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)

A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.25%via CSAF
CVE-2024-20267High· 8.6
2y ago

Cisco NX-OS Software MPLS IPv6 Denial of Serice Vulnerability

A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traff…

▾ TwilightCisco · Cisco Nexus 3000 Series SwitchesEPSS 0.93%via CSAF
CVE-2023-20268Medium· 4.7
3y ago

Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)

A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…

▾ SunlitCisco · Cisco Business Wireless Access Point SoftwareEPSS 0.24%via CSAF
CVE-2023-20176Medium· 5.8
3y ago

Cisco Aironet Access Points Denial of Service

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…

▾ SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.65%via CSAF
CVE-2023-20033High· 8.6
3y ago

Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Switches Denial of Service Vulnerability

A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.65%via CSAF
CVE-2023-20094Medium· 4.3
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.27%via CSAF
CVE-2023-20093Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20092Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20091Medium· 5.1
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2023-20090Medium· 6.7
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.21%via CSAF
CVE-2023-20004Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…

▾ SunlitCisco · Cisco RoomOS SoftwareEPSS 0.19%via CSAF
CVE-2023-20035High· 7.8
3y ago

Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2023-20035)

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.22%via CSAF
CVE-2023-20056Medium· 6.5
3y ago

Cisco Access Point Software Denial of Service

A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input v…

▾ SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.26%via CSAF
CVE-2023-20112High· 7.4
3y ago

Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain pa…

▾ TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.30%via CSAF
CVE-2023-20097Medium· 4.6
3y ago

Cisco Access Points (AP) Command Injection Vulnerability

A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands tha…

▾ SunlitCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 0.24%via CSAF
CVE-2023-20002Medium· 4.4
3y ago

Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.16%via CSAF
CVE-2023-20008Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …

▾ SunlitCisco · Cisco RoomOS SoftwareEPSS 0.19%via CSAF
CVE-2022-20955Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …

▾ SunlitCisco · Cisco RoomOS SoftwareEPSS 0.44%via CSAF
CVE-2022-20954Medium· 4.4
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.44%via CSAF
CVE-2022-20953Medium· 5.0
3y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability

Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.43%via CSAF
CVEs tagged “vendor-advisory” — page 5 · VulnSea