CVE-2022-20969
- EPSS 0.04%
- Veröffentlicht 04.11.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:43:56
A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsa...
CVE-2022-20773
- EPSS 1.23%
- Veröffentlicht 21.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:43:31
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacke...
CVE-2021-40126
- EPSS 0.15%
- Veröffentlicht 04.11.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:23:37
A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on...
CVE-2021-1474
- EPSS 0.33%
- Veröffentlicht 08.04.2021 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:44:26
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information abo...
CVE-2021-1475
- EPSS 0.18%
- Veröffentlicht 08.04.2021 04:15:13
- Zuletzt bearbeitet 21.11.2024 05:44:26
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information abo...
CVE-2021-1350
- EPSS 0.35%
- Veröffentlicht 20.01.2021 20:15:17
- Zuletzt bearbeitet 21.11.2024 05:44:09
A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could...
CVE-2020-3337
- EPSS 0.06%
- Veröffentlicht 18.06.2020 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:30:49
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is se...
CVE-2020-3246
- EPSS 0.16%
- Veröffentlicht 06.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:30:38
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insufficient validat...
CVE-2019-1807
- EPSS 0.42%
- Veröffentlicht 03.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:25
A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected app...
CVE-2019-1792
- EPSS 0.14%
- Veröffentlicht 18.04.2019 01:29:02
- Zuletzt bearbeitet 21.11.2024 04:37:23
A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella. The vulnerability is due to insufficient validat...