From e15ea130311a138d9b8b1eaa64e09da5db8179c8 Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Thu, 18 May 2023 04:00:38 +0000 Subject: [PATCH] Auto-Update: 2023-05-18 04:00:35.008453+00:00 --- CVE-2023/CVE-2023-200xx/CVE-2023-20003.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-200xx/CVE-2023-20024.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-200xx/CVE-2023-20077.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-200xx/CVE-2023-20087.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20106.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20110.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20156.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20157.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20158.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20159.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20160.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20161.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20162.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20163.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20164.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20166.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20167.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20171.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20172.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20173.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20174.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20182.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20183.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20184.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-201xx/CVE-2023-20189.json | 55 ++++++++++++++++++ CVE-2023/CVE-2023-25xx/CVE-2023-2509.json | 4 +- CVE-2023/CVE-2023-269xx/CVE-2023-26964.json | 6 +- CVE-2023/CVE-2023-272xx/CVE-2023-27217.json | 20 +++++++ CVE-2023/CVE-2023-27xx/CVE-2023-2757.json | 63 +++++++++++++++++++++ CVE-2023/CVE-2023-298xx/CVE-2023-29857.json | 24 ++++++++ CVE-2023/CVE-2023-317xx/CVE-2023-31729.json | 24 ++++++++ README.md | 40 ++++++++++--- 32 files changed, 1545 insertions(+), 11 deletions(-) create mode 100644 CVE-2023/CVE-2023-200xx/CVE-2023-20003.json create mode 100644 CVE-2023/CVE-2023-200xx/CVE-2023-20024.json create mode 100644 CVE-2023/CVE-2023-200xx/CVE-2023-20077.json create mode 100644 CVE-2023/CVE-2023-200xx/CVE-2023-20087.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20106.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20110.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20156.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20157.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20158.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20159.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20160.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20161.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20162.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20163.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20164.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20166.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20167.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20171.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20172.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20173.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20174.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20182.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20183.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20184.json create mode 100644 CVE-2023/CVE-2023-201xx/CVE-2023-20189.json create mode 100644 CVE-2023/CVE-2023-272xx/CVE-2023-27217.json create mode 100644 CVE-2023/CVE-2023-27xx/CVE-2023-2757.json create mode 100644 CVE-2023/CVE-2023-298xx/CVE-2023-29857.json create mode 100644 CVE-2023/CVE-2023-317xx/CVE-2023-31729.json diff --git a/CVE-2023/CVE-2023-200xx/CVE-2023-20003.json b/CVE-2023/CVE-2023-200xx/CVE-2023-20003.json new file mode 100644 index 00000000000..65f9bcc0e37 --- /dev/null +++ b/CVE-2023/CVE-2023-200xx/CVE-2023-20003.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20003", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.477", + "lastModified": "2023-05-18T03:15:09.477", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vulnerability is due to a logic error with the social login implementation. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to access the Guest Portal without authentication." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N", + "attackVector": "ADJACENT_NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 4.7, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 1.4 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-288" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cbw-auth-bypass-ggnAfdZ", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-200xx/CVE-2023-20024.json b/CVE-2023/CVE-2023-200xx/CVE-2023-20024.json new file mode 100644 index 00000000000..7f1a3020fa6 --- /dev/null +++ b/CVE-2023/CVE-2023-200xx/CVE-2023-20024.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20024", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.590", + "lastModified": "2023-05-18T03:15:09.590", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface.\r For more information about these vulnerabilities, see the Details section of this advisory.\r " + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-200xx/CVE-2023-20077.json b/CVE-2023/CVE-2023-200xx/CVE-2023-20077.json new file mode 100644 index 00000000000..3613aa95312 --- /dev/null +++ b/CVE-2023/CVE-2023-200xx/CVE-2023-20077.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20077", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.667", + "lastModified": "2023-05-18T03:15:09.667", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.\r These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.\r " + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "NONE", + "availabilityImpact": "NONE", + "baseScore": 4.9, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.6 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-37" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-dwnld-Srcdnkd2", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-200xx/CVE-2023-20087.json b/CVE-2023/CVE-2023-200xx/CVE-2023-20087.json new file mode 100644 index 00000000000..58874206c92 --- /dev/null +++ b/CVE-2023/CVE-2023-200xx/CVE-2023-20087.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20087", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.750", + "lastModified": "2023-05-18T03:15:09.750", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.\r These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.\r " + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "NONE", + "availabilityImpact": "NONE", + "baseScore": 4.9, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.6 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-37" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-dwnld-Srcdnkd2", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20106.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20106.json new file mode 100644 index 00000000000..916300dec92 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20106.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20106", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.820", + "lastModified": "2023-05-18T03:15:09.820", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device.\r For more information about these vulnerabilities, see the Details section of this advisory.\r " + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-602" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-delete-read-PK5ghDDd", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20110.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20110.json new file mode 100644 index 00000000000..b40bbf77da6 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20110.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20110", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.900", + "lastModified": "2023-05-18T03:15:09.900", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read sensitive data on the underlying database." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "NONE", + "availabilityImpact": "NONE", + "baseScore": 6.5, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 3.6 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-sql-X9MmjSYh", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20156.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20156.json new file mode 100644 index 00000000000..3b2ef59e556 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20156.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20156", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:09.973", + "lastModified": "2023-05-18T03:15:09.973", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20157.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20157.json new file mode 100644 index 00000000000..de76550cad9 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20157.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20157", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.047", + "lastModified": "2023-05-18T03:15:10.047", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20158.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20158.json new file mode 100644 index 00000000000..d44f5e7f567 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20158.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20158", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.123", + "lastModified": "2023-05-18T03:15:10.123", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20159.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20159.json new file mode 100644 index 00000000000..54873415678 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20159.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20159", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.190", + "lastModified": "2023-05-18T03:15:10.190", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20160.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20160.json new file mode 100644 index 00000000000..9ca1f8014ae --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20160.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20160", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.267", + "lastModified": "2023-05-18T03:15:10.267", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20161.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20161.json new file mode 100644 index 00000000000..ebc45b637a6 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20161.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20161", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.337", + "lastModified": "2023-05-18T03:15:10.337", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20162.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20162.json new file mode 100644 index 00000000000..e3577e50f88 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20162.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20162", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.413", + "lastModified": "2023-05-18T03:15:10.413", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20163.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20163.json new file mode 100644 index 00000000000..2a4704dd0a7 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20163.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20163", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.480", + "lastModified": "2023-05-18T03:15:10.480", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "HIGH", + "availabilityImpact": "NONE", + "baseScore": 6.5, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 5.2 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-78" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-sRQnsEU9", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20164.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20164.json new file mode 100644 index 00000000000..0b6ad94b771 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20164.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20164", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.547", + "lastModified": "2023-05-18T03:15:10.547", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "HIGH", + "availabilityImpact": "NONE", + "baseScore": 6.5, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 5.2 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-78" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-sRQnsEU9", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20166.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20166.json new file mode 100644 index 00000000000..eec2657ef1d --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20166.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20166", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.617", + "lastModified": "2023-05-18T03:15:10.617", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N", + "attackVector": "LOCAL", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "HIGH", + "availabilityImpact": "NONE", + "baseScore": 6.0, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 0.8, + "impactScore": 5.2 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-24" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-ZTUgMYhu", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20167.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20167.json new file mode 100644 index 00000000000..1891a505d22 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20167.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20167", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.690", + "lastModified": "2023-05-18T03:15:10.690", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N", + "attackVector": "LOCAL", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "HIGH", + "availabilityImpact": "NONE", + "baseScore": 6.0, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 0.8, + "impactScore": 5.2 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-24" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-ZTUgMYhu", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20171.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20171.json new file mode 100644 index 00000000000..122ba005891 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20171.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20171", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.763", + "lastModified": "2023-05-18T03:15:10.763", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-602" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-delete-read-PK5ghDDd", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20172.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20172.json new file mode 100644 index 00000000000..68cc443a19c --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20172.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20172", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.830", + "lastModified": "2023-05-18T03:15:10.830", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-602" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-delete-read-PK5ghDDd", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20173.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20173.json new file mode 100644 index 00000000000..7ffcdb7de01 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20173.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20173", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.893", + "lastModified": "2023-05-18T03:15:10.893", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "NONE", + "availabilityImpact": "NONE", + "baseScore": 4.9, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.6 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-611" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-696OZTCm", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20174.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20174.json new file mode 100644 index 00000000000..90c86e68aba --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20174.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20174", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:10.957", + "lastModified": "2023-05-18T03:15:10.957", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "HIGH", + "integrityImpact": "NONE", + "availabilityImpact": "NONE", + "baseScore": 4.9, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.6 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-611" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-696OZTCm", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20182.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20182.json new file mode 100644 index 00000000000..e75b13459e3 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20182.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20182", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:11.023", + "lastModified": "2023-05-18T03:15:11.023", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-285" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-multiple-kTQkGU3", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20183.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20183.json new file mode 100644 index 00000000000..046ab980d17 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20183.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20183", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:11.090", + "lastModified": "2023-05-18T03:15:11.090", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-285" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-multiple-kTQkGU3", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20184.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20184.json new file mode 100644 index 00000000000..55a142e6003 --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20184.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20184", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:11.150", + "lastModified": "2023-05-18T03:15:11.150", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 5.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 2.5 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-285" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-multiple-kTQkGU3", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-201xx/CVE-2023-20189.json b/CVE-2023/CVE-2023-201xx/CVE-2023-20189.json new file mode 100644 index 00000000000..b772bfa1bcf --- /dev/null +++ b/CVE-2023/CVE-2023-201xx/CVE-2023-20189.json @@ -0,0 +1,55 @@ +{ + "id": "CVE-2023-20189", + "sourceIdentifier": "ykramarz@cisco.com", + "published": "2023-05-18T03:15:11.207", + "lastModified": "2023-05-18T03:15:11.207", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected device. These vulnerabilities are due to improper validation of requests that are sent to the web interface. For more information about these vulnerabilities, see the Details section of this advisory." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "NONE", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "NONE", + "integrityImpact": "NONE", + "availabilityImpact": "HIGH", + "baseScore": 8.6, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.9, + "impactScore": 4.0 + } + ] + }, + "weaknesses": [ + { + "source": "ykramarz@cisco.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-120" + } + ] + } + ], + "references": [ + { + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg-web-multi-S9g4Nkgv", + "source": "ykramarz@cisco.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-25xx/CVE-2023-2509.json b/CVE-2023/CVE-2023-25xx/CVE-2023-2509.json index 3fe8830a1cf..58198ee426d 100644 --- a/CVE-2023/CVE-2023-25xx/CVE-2023-2509.json +++ b/CVE-2023/CVE-2023-25xx/CVE-2023-2509.json @@ -2,7 +2,7 @@ "id": "CVE-2023-2509", "sourceIdentifier": "security@asustor.com", "published": "2023-05-17T07:15:08.567", - "lastModified": "2023-05-17T12:46:46.567", + "lastModified": "2023-05-18T02:15:12.117", "vulnStatus": "Awaiting Analysis", "descriptions": [ { @@ -48,7 +48,7 @@ ], "references": [ { - "url": "https://https://www.asustor.com/security/security_advisory_detail?id=22", + "url": "https://www.asustor.com/security/security_advisory_detail?id=22", "source": "security@asustor.com" } ] diff --git a/CVE-2023/CVE-2023-269xx/CVE-2023-26964.json b/CVE-2023/CVE-2023-269xx/CVE-2023-26964.json index 1e1c189f3c6..7496ebd5d9b 100644 --- a/CVE-2023/CVE-2023-269xx/CVE-2023-26964.json +++ b/CVE-2023/CVE-2023-269xx/CVE-2023-26964.json @@ -2,7 +2,7 @@ "id": "CVE-2023-26964", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-11T14:15:07.677", - "lastModified": "2023-05-07T03:15:13.940", + "lastModified": "2023-05-18T03:15:11.277", "vulnStatus": "Modified", "descriptions": [ { @@ -77,6 +77,10 @@ "Issue Tracking" ] }, + { + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZHBAE7LQARMPUEEV4TWET4D7G6WCWBUD/", + "source": "cve@mitre.org" + }, { "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZYRZ5Y2ALATKKPIITAFAJIS4TR4LUAHO/", "source": "cve@mitre.org" diff --git a/CVE-2023/CVE-2023-272xx/CVE-2023-27217.json b/CVE-2023/CVE-2023-272xx/CVE-2023-27217.json new file mode 100644 index 00000000000..a118283515b --- /dev/null +++ b/CVE-2023/CVE-2023-272xx/CVE-2023-27217.json @@ -0,0 +1,20 @@ +{ + "id": "CVE-2023-27217", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-05-18T03:15:11.453", + "lastModified": "2023-05-18T03:15:11.453", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-27xx/CVE-2023-2757.json b/CVE-2023/CVE-2023-27xx/CVE-2023-2757.json new file mode 100644 index 00000000000..8f076783df0 --- /dev/null +++ b/CVE-2023/CVE-2023-27xx/CVE-2023-2757.json @@ -0,0 +1,63 @@ +{ + "id": "CVE-2023-2757", + "sourceIdentifier": "security@wordfence.com", + "published": "2023-05-18T03:15:11.513", + "lastModified": "2023-05-18T03:15:11.513", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "The Waiting: One-click countdowns plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'saveLang' functions in versions up to, and including, 0.6.2. This could lead to Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for subscriber-level attackers to access functions to save plugin data that can potentially lead to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "security@wordfence.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 7.4, + "baseSeverity": "HIGH" + }, + "exploitabilityScore": 3.1, + "impactScore": 3.7 + } + ] + }, + "weaknesses": [ + { + "source": "security@wordfence.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-862" + } + ] + } + ], + "references": [ + { + "url": "https://plugins.trac.wordpress.org/browser/waiting/tags/0.6.2/templates/templates.php#L426", + "source": "security@wordfence.com" + }, + { + "url": "https://plugins.trac.wordpress.org/browser/waiting/tags/0.6.2/waiting.php#L544", + "source": "security@wordfence.com" + }, + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/38cc5a39-6ec3-4ce9-b9ad-d4ca5dafe9a7?source=cve", + "source": "security@wordfence.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-298xx/CVE-2023-29857.json b/CVE-2023/CVE-2023-298xx/CVE-2023-29857.json new file mode 100644 index 00000000000..d29012073df --- /dev/null +++ b/CVE-2023/CVE-2023-298xx/CVE-2023-29857.json @@ -0,0 +1,24 @@ +{ + "id": "CVE-2023-29857", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-05-18T02:15:10.907", + "lastModified": "2023-05-18T02:15:10.907", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "An issue in Teslamate v1.27.1 allows attackers to obtain sensitive information via directly accessing the teslamate link." + } + ], + "metrics": {}, + "references": [ + { + "url": "http://leegt.synology.me:4000/", + "source": "cve@mitre.org" + }, + { + "url": "https://github.com/Langangago/Cve-number/blob/main/README.md", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-317xx/CVE-2023-31729.json b/CVE-2023/CVE-2023-317xx/CVE-2023-31729.json new file mode 100644 index 00000000000..f5eb2684c05 --- /dev/null +++ b/CVE-2023/CVE-2023-317xx/CVE-2023-31729.json @@ -0,0 +1,24 @@ +{ + "id": "CVE-2023-31729", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-05-18T02:15:12.380", + "lastModified": "2023-05-18T02:15:12.380", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection." + } + ], + "metrics": {}, + "references": [ + { + "url": "http://totolink.com", + "source": "cve@mitre.org" + }, + { + "url": "https://github.com/D2y6p/CVE/blob/main/Totolink/CVE-2023-31729/CVE-2023-31729.md", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index a41aeb6a624..5ec570c3ec4 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-05-18T02:00:28.864529+00:00 +2023-05-18T04:00:35.008453+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-05-18T01:15:09.163000+00:00 +2023-05-18T03:15:11.513000+00:00 ``` ### Last Data Feed Release @@ -29,22 +29,46 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -215560 +215589 ``` ### CVEs added in the last Commit -Recently added CVEs: `3` +Recently added CVEs: `29` -* [CVE-2022-4870](CVE-2022/CVE-2022-48xx/CVE-2022-4870.json) (`2023-05-18T00:15:09.103`) -* [CVE-2023-29985](CVE-2023/CVE-2023-299xx/CVE-2023-29985.json) (`2023-05-18T01:15:09.117`) -* [CVE-2023-30124](CVE-2023/CVE-2023-301xx/CVE-2023-30124.json) (`2023-05-18T01:15:09.163`) +* [CVE-2023-20077](CVE-2023/CVE-2023-200xx/CVE-2023-20077.json) (`2023-05-18T03:15:09.667`) +* [CVE-2023-20087](CVE-2023/CVE-2023-200xx/CVE-2023-20087.json) (`2023-05-18T03:15:09.750`) +* [CVE-2023-20106](CVE-2023/CVE-2023-201xx/CVE-2023-20106.json) (`2023-05-18T03:15:09.820`) +* [CVE-2023-20110](CVE-2023/CVE-2023-201xx/CVE-2023-20110.json) (`2023-05-18T03:15:09.900`) +* [CVE-2023-20156](CVE-2023/CVE-2023-201xx/CVE-2023-20156.json) (`2023-05-18T03:15:09.973`) +* [CVE-2023-20157](CVE-2023/CVE-2023-201xx/CVE-2023-20157.json) (`2023-05-18T03:15:10.047`) +* [CVE-2023-20158](CVE-2023/CVE-2023-201xx/CVE-2023-20158.json) (`2023-05-18T03:15:10.123`) +* [CVE-2023-20159](CVE-2023/CVE-2023-201xx/CVE-2023-20159.json) (`2023-05-18T03:15:10.190`) +* [CVE-2023-20160](CVE-2023/CVE-2023-201xx/CVE-2023-20160.json) (`2023-05-18T03:15:10.267`) +* [CVE-2023-20161](CVE-2023/CVE-2023-201xx/CVE-2023-20161.json) (`2023-05-18T03:15:10.337`) +* [CVE-2023-20162](CVE-2023/CVE-2023-201xx/CVE-2023-20162.json) (`2023-05-18T03:15:10.413`) +* [CVE-2023-20163](CVE-2023/CVE-2023-201xx/CVE-2023-20163.json) (`2023-05-18T03:15:10.480`) +* [CVE-2023-20164](CVE-2023/CVE-2023-201xx/CVE-2023-20164.json) (`2023-05-18T03:15:10.547`) +* [CVE-2023-20166](CVE-2023/CVE-2023-201xx/CVE-2023-20166.json) (`2023-05-18T03:15:10.617`) +* [CVE-2023-20167](CVE-2023/CVE-2023-201xx/CVE-2023-20167.json) (`2023-05-18T03:15:10.690`) +* [CVE-2023-20171](CVE-2023/CVE-2023-201xx/CVE-2023-20171.json) (`2023-05-18T03:15:10.763`) +* [CVE-2023-20172](CVE-2023/CVE-2023-201xx/CVE-2023-20172.json) (`2023-05-18T03:15:10.830`) +* [CVE-2023-20173](CVE-2023/CVE-2023-201xx/CVE-2023-20173.json) (`2023-05-18T03:15:10.893`) +* [CVE-2023-20174](CVE-2023/CVE-2023-201xx/CVE-2023-20174.json) (`2023-05-18T03:15:10.957`) +* [CVE-2023-20182](CVE-2023/CVE-2023-201xx/CVE-2023-20182.json) (`2023-05-18T03:15:11.023`) +* [CVE-2023-20183](CVE-2023/CVE-2023-201xx/CVE-2023-20183.json) (`2023-05-18T03:15:11.090`) +* [CVE-2023-20184](CVE-2023/CVE-2023-201xx/CVE-2023-20184.json) (`2023-05-18T03:15:11.150`) +* [CVE-2023-20189](CVE-2023/CVE-2023-201xx/CVE-2023-20189.json) (`2023-05-18T03:15:11.207`) +* [CVE-2023-27217](CVE-2023/CVE-2023-272xx/CVE-2023-27217.json) (`2023-05-18T03:15:11.453`) +* [CVE-2023-2757](CVE-2023/CVE-2023-27xx/CVE-2023-2757.json) (`2023-05-18T03:15:11.513`) ### CVEs modified in the last Commit -Recently modified CVEs: `0` +Recently modified CVEs: `2` +* [CVE-2023-2509](CVE-2023/CVE-2023-25xx/CVE-2023-2509.json) (`2023-05-18T02:15:12.117`) +* [CVE-2023-26964](CVE-2023/CVE-2023-269xx/CVE-2023-26964.json) (`2023-05-18T03:15:11.277`) ## Download and Usage