Specially crafted traffic can send Cisco Secure Firewall’s Snort 3 inspection engine into an infinite loop, knocking out packet inspection until the watchdog restarts the process, with no login needed and no workaround.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability
A parsing flaw in Cisco FTD’s geolocation-based RA VPN feature lets an unauthenticated attacker craft HTTP connections that dodge location-based access controls, reaching networks meant to be geo-restricted.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series TLS 1.3 Cipher Denial of Service Vulnerability
Firewalls running ASA or FTD on Firepower 3100/4200 hardware can be knocked offline for new SSL/TLS and VPN sessions by flooding a non-default TLS 1.3 cipher until the device needs a reboot.
Cisco Catalyst Center Unauthenticated API Access Vulnerability
An unauthenticated API endpoint in Cisco Catalyst Center lets remote attackers read or rewrite the outgoing proxy configuration, potentially rerouting or intercepting outbound traffic.
Cisco Webex Meeting Client Join Certificate Validation Vulnerability
Weak certificate checks in Webex Meetings’ join process could let someone sharing your local network slip into a meeting posing as a legitimate user, without needing credentials.
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Authenticated users of Cisco ISE and ISE-PIC can inject stored scripts or bypass permission checks to alter device configuration, with no workaround available until patched.
Cisco Catalyst Center Insufficient Access Control Vulnerability
An authenticated attacker can send crafted HTTP requests to an internal service on Cisco Catalyst Center deployments with Disaster Recovery enabled, letting them read and alter managed data.
Cisco Catalyst SD-WAN Manager Arbitrary File Creation Vulnerability
An authenticated attacker can abuse an API validation flaw in Cisco Catalyst SD-WAN Manager to traverse directories and write files anywhere on the underlying system, with no workaround available.
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
A read-only CLI account on Cisco Catalyst SD-WAN Manager can be abused to overwrite arbitrary files on disk, opening a path to root-level control of the device.
Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability
Cisco Catalyst SD-WAN Manager fails to properly validate certificates used for Smart Licensing, letting an attacker positioned on the network path intercept device credentials headed to Cisco’s cloud services.