CVE-2022-20797 – Cisco Secure Network Analytics Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-20797
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system. This vulnerability is due to insufficient user input validation by the web-based management interface of the affected software. An attacker could exploit this vulnerability by injecting arbitrary commands in the web-based management interface. A successful exploit could allow the attacker to make configuration changes on the affected device or cause certain services to restart unexpectedly. Una vulnerabilidad en la interfaz de gestión basada en la web de Cisco Secure Network Analytics, anteriormente Cisco Stealthwatch Enterprise, podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios como administrador en el sistema operativo subyacente. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK • CWE-20: Improper Input Validation CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-20765 – Cisco UCS Director JavaScript Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2022-20765
A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a cross-site scripting attack on an affected system. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to affected web applications. A successful exploit could allow the attacker to rewrite web page content, access sensitive information stored in the applications, and alter data by submitting forms. Una vulnerabilidad en las aplicaciones web de Cisco UCS Director podría permitir a un atacante remoto autentificado realizar un ataque de scripting entre sitios en un sistema afectado. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-UCS-XSS-uQSME3L7 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) •
CVE-2022-20674 – Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilities
https://notcve.org/view.php?id=CVE-2022-20674
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. Varias vulnerabilidades en la interfaz de gestión basada en la web del software Cisco Common Services Platform Collector (CSPC) podrían permitir a un atacante remoto no autenticado realizar un ataque de secuencias de comandos en sitios cruzados (XSS) contra un usuario de la interfaz. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-multi-xss-tyDFjhwb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-20673 – Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilities
https://notcve.org/view.php?id=CVE-2022-20673
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. Varias vulnerabilidades en la interfaz de gestión basada en la web del software Cisco Common Services Platform Collector (CSPC) podrían permitir a un atacante remoto no autenticado realizar un ataque de secuencias de comandos en sitios cruzados (XSS) contra un usuario de la interfaz. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-multi-xss-tyDFjhwb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-20672 – Cisco Common Services Platform Collector Cross-Site Scripting Vulnerabilities
https://notcve.org/view.php?id=CVE-2022-20672
Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information. Múltiples vulnerabilidades en la interfaz de gestión basada en la web del software Cisco Common Services Platform Collector (CSPC) podrían permitir a un atacante remoto no autenticado realizar un ataque de secuencias de comandos en sitios cruzados (XSS) contra un usuario de la interfaz. • https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-multi-xss-tyDFjhwb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •