CVE-2021-1454
- EPSS 0.11%
- Veröffentlicht 24.03.2021 20:15:15
- Zuletzt bearbeitet 21.11.2024 05:44:24
Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain...
CVE-2021-1392
- EPSS 0.03%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:14
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrati...
CVE-2021-1394
- EPSS 0.07%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:15
A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the web management interfac...
CVE-2021-1398
- EPSS 0.07%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:15
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of...
CVE-2021-1403
- EPSS 0.11%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:16
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulner...
CVE-2021-1431
- EPSS 0.38%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:20
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of m...
CVE-2021-1432
- EPSS 0.06%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:21
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a ...
CVE-2021-1433
- EPSS 0.67%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:21
A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device process...
CVE-2021-1434
- EPSS 0.06%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:21
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific C...
- EPSS 0.38%
- Veröffentlicht 24.03.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:44:21
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exp...