- EPSS 0.04%
- Published 24.09.2020 18:15:20
- Last modified 19.12.2024 13:52:35
A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permi...
CVE-2020-3508
- EPSS 0.08%
- Published 24.09.2020 18:15:20
- Last modified 21.11.2024 05:31:12
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent at...
CVE-2020-3422
- EPSS 1.02%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:01
A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the IP SLA responder to reuse an existing port, resulting in a denial of service (DoS) conditi...
CVE-2020-3423
- EPSS 0.06%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:02
A vulnerability in the implementation of the Lua interpreter that is integrated in Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code with root privileges on the underlying Linux operating system (OS) of an a...
CVE-2020-3425
- EPSS 0.98%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:02
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more info...
CVE-2020-3428
- EPSS 0.08%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:03
A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. ...
CVE-2020-3429
- EPSS 0.13%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:03
A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected d...
CVE-2020-3465
- EPSS 0.1%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:07
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this ...
CVE-2020-3474
- EPSS 0.17%
- Published 24.09.2020 18:15:19
- Last modified 21.11.2024 05:31:08
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang ...
CVE-2020-3407
- EPSS 1.26%
- Published 24.09.2020 18:15:18
- Last modified 21.11.2024 05:30:58
A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL th...