|
199211
|
8.2 |
HIGH
Network
|
cisco
|
nx-os
|
A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 auth…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-3165
|
2024-11-21 14:30 |
2020-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199212
|
5.9 |
MEDIUM
Network
|
cisco
|
unified_contact_center_enterprise
|
A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …
|
CWE-362
Race Condition
|
CVE-2020-3163
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199213
|
4.9 |
MEDIUM
Network
|
cisco
|
cloud_web_security
|
A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based manageme…
|
CWE-89
SQL Injection
|
CVE-2020-3154
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199214
|
6.7 |
MEDIUM
Local
|
cisco
|
enterprise_network_function_virtualization_infrastructure
|
A vulnerability in the upgrade component of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to install a malicious file when upgrading. The vulnerabi…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-3138
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199215
|
5.3 |
MEDIUM
Network
|
cisco
|
meeting_server
|
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) co…
|
CWE-20
Improper Input Validation
|
CVE-2020-3160
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199216
|
6.1 |
MEDIUM
Network
|
cisco
|
finesse
|
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based m…
|
CWE-79
Cross-site Scripting
|
CVE-2020-3159
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199217
|
9.1 |
CRITICAL
Network
|
cisco
|
smart_software_manager_on-prem
|
A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-priv…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-3158
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199218
|
6.1 |
MEDIUM
Network
|
cisco
|
identity_services_engine
|
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the impr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-3156
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199219
|
6.5 |
MEDIUM
Local
|
cisco
|
anyconnect_secure_mobility_client
|
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories w…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-3153
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199220
|
5.9 |
MEDIUM
Network
|
cisco
|
cloud_email_security email_security_appliance
|
A vulnerability in the email message scanning feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a temporary denial of…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-3132
|
2024-11-21 14:30 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|