Latest CVE Feed
-
5.4
MEDIUMCVE-2022-20966
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vu... Read more
Affected Products : identity_services_engine- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-20965
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access con... Read more
Affected Products : identity_services_engine- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-20964
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of u... Read more
Affected Products : identity_services_engine- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2022-20963
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ... Read more
Affected Products : identity_services_engine- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-20962
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient i... Read more
Affected Products : identity_services_engine- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-20961
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. Thi... Read more
Affected Products : identity_services_engine- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2022-20960
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of cert... Read more
- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2022-20959
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.... Read more
Affected Products : identity_services_engine- Published: Oct. 26, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-20958
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to i... Read more
- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2022-20956
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web... Read more
Affected Products : identity_services_engine- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-20955
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more informat... Read more
- Published: Oct. 26, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2022-20954
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more informat... Read more
- Published: Oct. 26, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2022-20953
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more informat... Read more
- Published: Oct. 26, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2022-20952
A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic o... Read more
- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2022-20951
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to ins... Read more
- Published: Nov. 04, 2022
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2022-20950
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 detection engine to restart. This vulnerability is due to a lack of error-check... Read more
Affected Products : firepower_threat_defense- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2022-20949
A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because ... Read more
Affected Products : firepower_threat_defense- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2022-20947
A vulnerability in dynamic access policies (DAP) functionality of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting... Read more
- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2022-20946
A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. ... Read more
Affected Products : firepower_threat_defense- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2022-20945
A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to... Read more
- Published: Sep. 30, 2022
- Modified: Nov. 21, 2024