An authenticated user with only low-level access to Cisco Catalyst SD-WAN Manager can abuse a flawed API to write files anywhere on the underlying system via directory traversal.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
A low-privilege, read-only CLI user on Cisco Catalyst SD-WAN Manager can overwrite arbitrary files and escalate straight to root, with no workaround available other than upgrading.
Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability
Cisco Catalyst SD-WAN Manager fails to properly validate certificates for its Smart Licensing connections, letting an attacker positioned to intercept internet traffic read the credentials used to reach Cisco’s cloud services.
Cisco Duo Self-Service Portal Command Injection Vulnerability
An unauthenticated attacker could inject arbitrary commands into emails sent from Cisco Duo’s cloud-hosted self-service portal, letting them slip malicious content to unsuspecting recipients.
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
A crafted RADIUS authentication request sent to any network device using Cisco ISE for AAA can force the ISE process to reload, knocking out authentication network-wide with no login needed.
Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass Vulnerability
Missing signature checks during boot on these Catalyst switches let a privileged local user or someone with physical access plant code that survives reboots and undermines the secure boot chain of trust.
Cisco IOS Software Industrial Ethernet Switch Device Manager Privilege Escalation Vulnerability
An authenticated user with only mid-level access on Cisco Industrial Ethernet switches can send a crafted HTTP request to the Device Manager and gain full administrative control.
Cisco IOS XE Software Bootstrap Arbitrary File Write Vulnerability
A tampered bootstrap file loaded during initial SD-WAN or SD-Routing setup lets an already-authenticated local user on a Cisco IOS XE device write arbitrary files to the underlying OS.
Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers ARP Denial
An unauthenticated attacker on the same network segment can flood an ASR 903 router with crafted ARP messages, exhausting memory and forcing a route switch processor reload.
Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol Denial of
An unauthenticated attacker within radio or wired reach of a joined access point can send a malformed CDP packet that crashes the wireless controller, dropping the entire Wi-Fi network it manages.