cisco-sa-20200318-vmanage-cypher-inject
Cisco SD-WAN Solution vManage SQL Injection Vulnerability
CVEs:CVE-2019-16012
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-271450 | affected | Cisco | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
Cisco SD-WAN Solution vManage SQL Injection Vulnerability
CVEs:CVE-2019-16012
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-271450 | affected | Cisco | — | — |
Cisco SD-WAN Solution vManage Stored Cross-Site Scripting Vulnerability
CVEs:CVE-2019-16010
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-271450 | affected | Cisco | — | — |
Cisco SD-WAN Solution Buffer Overflow Vulnerability
CVEs:CVE-2020-3264
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Command Injection Vulnerability
CVEs:CVE-2020-3266
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco SD-WAN Solution Privilege Escalation Vulnerability
CVEs:CVE-2020-3265
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-238692 | affected | Cisco | — | — |
Cisco Webex Network Recording Player and Cisco Webex Player Arbitrary Code Execution Vulnerabilities
CVEs:CVE-2020-3127CVE-2020-3128
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-100455 | affected | Cisco | — | — |
| CVRFPID-96064 | affected | Cisco | — | — |
Cisco ESA, Cisco WSA, and Cisco SMA GUI Denial of Service Vulnerability
CVEs:CVE-2020-3164
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189789 | affected | Cisco | — | — |
| CVRFPID-189790 | affected | Cisco | — | — |
| CVRFPID-189791 | affected | Cisco | — | — |
Cisco Prime Network Registrar Cross-Site Request Forgery Vulnerability
CVEs:CVE-2020-3148
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-195936 | affected | Cisco | — | — |
Cisco Email Security Appliance Uncontrolled Resource Exhaustion Vulnerability
CVEs:CVE-2020-3181
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-189790 | affected | Cisco | — | — |
Cisco IOS XR Software IPsec Packet Processor Denial of Service Vulnerability
CVEs:CVE-2020-3190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-5834 | affected | Cisco | — | — |
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
CVEs:CVE-2020-3157
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-111903 | affected | Cisco | — | — |
Cisco Prime Collaboration Provisioning Information Disclosure Vulnerability
CVEs:CVE-2020-3193
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-209583 | affected | Cisco | — | — |
Cisco Prime Collaboration Provisioning Cross-Site Scripting Vulnerability
CVEs:CVE-2020-3192
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-209583 | affected | Cisco | — | — |
Cisco Intelligent Proximity SSL Certificate Validation Vulnerability
CVEs:CVE-2020-3155
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-190570 | affected | Cisco | — | — |
| CVRFPID-190702 | affected | Cisco | — | — |
| CVRFPID-192127 | affected | Cisco | — | — |
| CVRFPID-203919 | affected | Cisco | — | — |
| CVRFPID-203922 | affected | Cisco | — | — |
| CVRFPID-210403 | affected | Cisco | — | — |
| CVRFPID-210554 | affected | Cisco | — | — |
| CVRFPID-210568 | affected | Cisco | — | — |
| CVRFPID-221064 | affected | Cisco | — | — |
| CVRFPID-228295 | affected | Cisco | — | — |
| CVRFPID-265365 | affected | Cisco | — | — |
| CVRFPID-276958 | affected | Cisco | — | — |
Cisco Remote PHY Device Software Command Injection Vulnerability
CVEs:CVE-2020-3176
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-245407 | affected | Cisco | — | — |
Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability
CVEs:CVE-2020-3185
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-191859 | affected | Cisco | — | — |
Cisco Webex Meetings Client for MacOS Information Disclosure Vulnerability
CVEs:CVE-2020-3182
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-228295 | affected | Cisco | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.