Latest CVE Feed
-
4.3
MEDIUMCVE-2021-1515
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, adjacent attacker to gain access to sensitive information. This vulnerability is due to improper access controls on API endpoints when Cisco SD-WAN vManage Software is runnin... Read more
Affected Products : sd-wan_vmanage- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-1514
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with Administrator privileges on the underlying operating system. This vulnerability is due to insufficient input ... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-1513
A vulnerability in the vDaemon process of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed ... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-1512
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system of an affected system. This vulnerability is due to insufficient validation of the user-supplied in... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-1511
Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Detail... Read more
Affected Products : vedge_100b_firmware vedge_100m_firmware vedge_100wm_firmware vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vedge_cloud_firmware sd-wan_vedge_router vedge_100 +7 more products- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-1510
Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Detail... Read more
Affected Products : vedge_100b_firmware vedge_100m_firmware vedge_100wm_firmware vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vedge_cloud_firmware sd-wan_vedge_router vedge_100 +7 more products- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-1509
Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Detail... Read more
Affected Products : vedge_100b_firmware vedge_100m_firmware vedge_100wm_firmware vedge_100_firmware vedge_1000_firmware vedge_2000_firmware vedge_5000_firmware vedge_cloud_firmware sd-wan_vedge_router vedge_100 +7 more products- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1508
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain una... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-1507
A vulnerability in an API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the application web-based interface. This vulnerability exists because the API ... Read more
Affected Products : sd-wan_vmanage- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1506
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain una... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-1505
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain una... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-1504
Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilit... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-1503
A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of val... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-1502
A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of valu... Read more
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-1501
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected device, resulting... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-1500
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL parameters in an ... Read more
- Published: Nov. 04, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-1499
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. A... Read more
- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-1496
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful ... Read more
Affected Products : anyconnect_secure_mobility_client- Published: May. 06, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-1495
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header ... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-1493
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnera... Read more
- Published: Apr. 29, 2021
- Modified: Nov. 21, 2024