CVE-2023-20273
- EPSS 89.63%
- Veröffentlicht 25.10.2023 18:17:23
- Zuletzt bearbeitet 28.10.2025 13:59:49
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vu...
- EPSS 99.57%
- Veröffentlicht 16.10.2023 16:15:10
- Zuletzt bearbeitet 28.10.2025 13:59:32
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that th...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-20235
- EPSS 0.51%
- Veröffentlicht 04.10.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:40:57
A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the roo...
CVE-2023-20186
- EPSS 0.59%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:46
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system...
CVE-2023-20187
- EPSS 0.65%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:46
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting...
CVE-2023-20202
- EPSS 0.24%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:49
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improp...
CVE-2023-20226
- EPSS 0.71%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:56
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of servi...
CVE-2023-20227
- EPSS 0.65%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:56
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper han...
CVE-2023-20231
- EPSS 0.74%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:40:57
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit t...