An unauthenticated but Layer 2-adjacent IS-IS peer can send a crafted packet to a Nexus 3000 or 9000 switch in standalone NX-OS mode and force the IS-IS process, and potentially the whole switch, to reload.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Sensitive Information Disclosure Vulnerability
A path-traversal flaw in the web interface of Cisco EPNM and Prime Infrastructure lets an authenticated, low-privileged user pull arbitrary files off the underlying server filesystem.
Cisco Duo Authentication Proxy Information Disclosure Vulnerability
A privileged attacker who can already read logs on a Duo Authentication Proxy host may find sensitive data left unmasked in debug log files, exposing confidentiality-sensitive information.
Cisco Identity Services Engine Arbitrary File Upload Vulnerability
An authenticated ISE administrator can abuse a flaw in the GUI’s file copy feature to write arbitrary files to the underlying device, with no workaround available.
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
An unauthenticated attacker who can reach TCP port 4786 on a Cisco switch running Smart Install client mode can crash it or run arbitrary code, with no credentials or workaround available.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Web Services Denial of Service Vulnerability
An unauthenticated attacker can crash a Cisco ASA or FTD firewall with a single crafted HTTP request to its web management interface or REST API, forcing a reload with no login required.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability
On Cisco ASA and FTD devices with a loopback interface configured, access control rules meant to block certain traffic can be bypassed, letting unauthenticated remote traffic reach that interface anyway.
Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Six flaws in IKEv2 VPN handling on Cisco IOS, IOS XE, ASA and FTD let an unauthenticated attacker crash the device or leak memory until it fails, with no workaround short of patching.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities
An admin who already has valid credentials on Cisco ASA or FTD firewalls can inject crafted commands that run as root on the underlying OS, turning administrative access into full system control.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability
A firewall’s DHCP client will crash from crafted DHCPv4 packets sent by anyone on the same segment, exhausting memory and needing a manual reboot to recover.