Latest CVE Feed
-
5.4
MEDIUMCVE-2021-1599
A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user. This vulnerability is due to insufficient input... Read more
Affected Products : unified_customer_voice_portal- Published: Jul. 22, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-1598
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS)... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-1597
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS)... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-1596
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS)... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-1595
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Video Surveillance 7000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS)... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-1594
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for sp... Read more
Affected Products : identity_services_engine- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2021-1593
A vulnerability in Cisco Packet Tracer for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the Windows system. This vu... Read more
Affected Products : packet_tracer- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-1592
A vulnerability in the way Cisco UCS Manager software handles SSH sessions could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management for esta... Read more
Affected Products : unified_computing_system unified_computing_system_64108 unified_computing_system_6454- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-1591
A vulnerability in the EtherChannel port subscription logic of Cisco Nexus 9500 Series Switches could allow an unauthenticated, remote attacker to bypass access control list (ACL) rules that are configured on an affected device. This vulnerability is due ... Read more
Affected Products : nx-os nexus_9500_16-slot nexus_9500_4-slot nexus_9500_8-slot nexus_9504 nexus_9508 nexus_9516- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-1590
A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulner... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nexus_3000 unified_computing_system nexus_5548p nexus_5548up nexus_5596up nexus_3048 +93 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-1589
A vulnerability in the disaster recovery feature of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain unauthorized access to user credentials. This vulnerability exists because access to API endpoints is not properly rest... Read more
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-1588
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to i... Read more
Affected Products : nx-os nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot nexus_3000 nexus_3048 nexus_31108pc-v nexus_31108tc-v nexus_31128pq nexus_3132c-z +57 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-1587
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnera... Read more
Affected Products : nx-os nexus_3000 nexus_3048 nexus_31108pc-v nexus_31108tc-v nexus_31128pq nexus_3132c-z nexus_3132q-v nexus_3132q-x\/3132q-xl nexus_3164q +53 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-1586
A vulnerability in the Multi-Pod or Multi-Site network configurations for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to unexpectedly restart the device, resultin... Read more
Affected Products : nx-os nx-os nexus_9000v nexus_92160yc-x nexus_92300yc nexus_92304qc nexus_92348gc-x nexus_9236c nexus_9272q nexus_93108tc-ex +32 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-1585
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for ... Read more
- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-1584
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient restrictions du... Read more
Affected Products : nx-os nx-os nexus_9000 nexus_9000v nexus_92160yc-x nexus_92300yc nexus_92304qc nexus_92348gc-x nexus_9236c nexus_9272q +33 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-1583
A vulnerability in the fabric infrastructure file system access control of Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to read arbitrary files on an affected system.... Read more
Affected Products : nx-os nx-os nexus_9000 nexus_9000v nexus_92160yc-x nexus_92300yc nexus_92304qc nexus_92348gc-x nexus_9236c nexus_9272q +33 more products- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-1582
A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability is due t... Read more
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-1581
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more in... Read more
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-1580
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more in... Read more
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024