Cisco Security Advisories · November 2020 — Cisco Security Advisories
58 advisories 60 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2020-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

cisco-sa-ucs-api-rce-UXwpeDHd

Cisco PSIRTHIGH2020-11-18

Cisco Integrated Management Controller Multiple Remote Code Execution Vulnerabilities

CVEs:CVE-2020-3470

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-191638 affected Cisco
CVRFPID-201970 affected Cisco
Upstream advisory

cisco-sa-webex-info-leak-PhpzB3sG

Cisco PSIRTHIGH2020-11-18

Cisco Webex Meetings and Cisco Webex Meetings Server Unauthorized Audio Information Exposure Vulnerability

CVEs:CVE-2020-3471

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190702 affected Cisco
CVRFPID-228295 affected Cisco
Upstream advisory

cisco-sa-webex-infodisc-4tvQzn4

Cisco PSIRTHIGH2020-11-18

Cisco Webex Meetings and Cisco Webex Meetings Server Information Disclosure Vulnerability

CVEs:CVE-2020-3441

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190702 affected Cisco
CVRFPID-228295 affected Cisco
Upstream advisory

cisco-sa-CIMC-CIV-pKDBe9x5

Cisco PSIRTHIGH2020-11-04

Cisco Integrated Management Controller Command Injection Vulnerability

CVEs:CVE-2020-3371

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-191638 affected Cisco
CVRFPID-201970 affected Cisco
Upstream advisory

cisco-sa-vepegr-4xynYLUj

Cisco PSIRTHIGH2020-11-04

Cisco SD-WAN Software Privilege Escalation Vulnerability

CVEs:CVE-2020-3595

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-vepescm-BjgQm4vJ

Cisco PSIRTHIGH2020-11-04

Cisco SD-WAN Software Privilege Escalation Vulnerability

CVEs:CVE-2020-3593

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-vepeshlg-tJghOQcA

Cisco PSIRTHIGH2020-11-04

Cisco SD-WAN Software Privilege Escalation Vulnerability

CVEs:CVE-2020-3600

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-vepestd-8C3J9Vc

Cisco PSIRTHIGH2020-11-04

Cisco SD-WAN Software Privilege Escalation Vulnerability

CVEs:CVE-2020-3594

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-238692 affected Cisco
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

cisco-sa-vsoln-arbfile-gtsEYxns

Cisco PSIRTHIGH2020-11-04

Cisco SD-WAN Software Arbitrary File Creation Vulnerability

CVEs:CVE-2020-26071

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-271450 affected Cisco
CVRFPID-278041 affected Cisco
CVRFPID-278078 affected Cisco
CVRFPID-278124 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.