|
197401
|
6.7 |
MEDIUM
Local
|
cisco
|
firepower_threat_defense adaptive_security_appliance_software firepower_extensible_operating_system
|
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to read or write arbitrary files on the underlying operating system (OS). The vulnerability is due to in…
|
CWE-20
Improper Input Validation
|
CVE-2020-3166
|
2024-11-21 14:30 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197402
|
8.2 |
HIGH
Network
|
cisco
|
nx-os
|
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 auth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-3165
|
2024-11-21 14:30 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197403
|
5.9 |
MEDIUM
Network
|
cisco
|
unified_contact_center_enterprise
|
A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …
|
CWE-362
Race Condition
|
CVE-2020-3163
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197404
|
4.9 |
MEDIUM
Network
|
cisco
|
cloud_web_security
|
A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based manageme…
|
CWE-89
SQL Injection
|
CVE-2020-3154
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197405
|
6.7 |
MEDIUM
Local
|
cisco
|
enterprise_network_function_virtualization_infrastructure
|
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerabi…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-3138
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197406
|
5.3 |
MEDIUM
Network
|
cisco
|
meeting_server
|
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) co…
|
CWE-20
Improper Input Validation
|
CVE-2020-3160
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197407
|
6.1 |
MEDIUM
Network
|
cisco
|
finesse
|
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based m…
|
CWE-79
Cross-site Scripting
|
CVE-2020-3159
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197408
|
9.1 |
CRITICAL
Network
|
cisco
|
smart_software_manager_on-prem
|
A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-priv…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-3158
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197409
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the impr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-3156
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197410
|
6.5 |
MEDIUM
Local
|
cisco
|
anyconnect_secure_mobility_client
|
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories w…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-3153
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|