A low-privileged lobby ambassador account on Cisco IOS XE Wireless Controllers can be used to delete any user account, including administrator ones, due to weak access control in that web interface.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Denial of Service Vulnerabilities
Five separate flaws in the AnyConnect VPN server on Meraki MX and Z series gateways let an unauthenticated attacker drop existing SSL VPN sessions and block new ones from connecting.
Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Session Takeover
Weak randomness and a race condition in the AnyConnect VPN login process on Meraki MX and Z Series devices let a remote attacker without credentials hijack or block another user’s VPN session.
Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability
Cisco NDFC fails to properly validate SSH host keys when talking to the switches it manages, letting a network-positioned attacker impersonate a device and harvest the credentials NDFC uses to log in.
Cisco Secure Network Analytics Manager API Authorization Vulnerability
A low-privileged authenticated user can abuse an under-protected API in Cisco Secure Network Analytics Manager to fabricate findings, letting them mask real alerts or trigger false ones.
Cisco Secure Network Analytics Manager Privilege Escalation Vulnerability
An authenticated administrator on Cisco Secure Network Analytics Manager or its virtual variant can send crafted input to the web management interface and run arbitrary commands as root on the host OS.
Cisco Unified Communications Products Command Injection Vulnerability
An authenticated CLI administrator on several Cisco Unified Communications platforms can craft command arguments that break out to root on the underlying OS, with no workaround available.
Cisco Unified Communications Products Privilege Escalation Vulnerability
An attacker with ESXi hypervisor admin rights can escalate from the restricted shell of several Cisco Unified Communications and Contact Center virtual appliances straight to root on the guest OS.
Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control
Cisco’s Cloud Connect component in Unified Contact Center Enterprise accepts crafted TCP data on a specific port with no authentication check, letting a remote attacker read or alter data on the device.
Cisco Unified Intelligence Center Privilege Escalation Vulnerabilities
Two flaws in Cisco Unified Intelligence Center let anyone already logged in with a low-privilege account reach reporting data and functions meant for other roles, affecting every contact-centre product that bundles the tool.