An unauthenticated attacker could inject arbitrary commands into emails sent from Cisco Duo’s cloud-hosted self-service portal, letting them slip malicious content to unsuspecting recipients.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
An unauthenticated attacker can send crafted RADIUS authentication requests to Cisco ISE and force the appliance to reload, knocking out authentication services with no workaround available.
Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass Vulnerability
Missing signature checks during boot on these Catalyst switches let a privileged local user or someone with physical access plant code that survives reboots and undermines the secure boot chain of trust.
Cisco IOS Software Industrial Ethernet Switch Device Manager Privilege Escalation Vulnerability
An authenticated user with only mid-level access on Cisco Industrial Ethernet switches can send a crafted HTTP request to the Device Manager and gain full administrative control.
Cisco IOS XE Software Bootstrap Arbitrary File Write Vulnerability
An authenticated local attacker on Cisco IOS XE devices running SD-WAN or SD-Routing can tamper with the bootstrap file loaded from flash to write arbitrary files to the operating system.
Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers ARP Denial of Service Vulnerability
Crafted ARP traffic aimed at Cisco ASR 903 routers running RSP3C can exhaust memory in the Cisco Express Forwarding process, forcing a route switch processor reload or full router outage.
Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol Denial of Service Vulnerability
A crafted CDP packet sent to a Cisco access point can crash the wireless controller managing it, knocking the whole wireless network offline until it reboots.
Cisco IOS XE Wireless Controller Software Unauthorized User Deletion Vulnerability
A low-privileged lobby ambassador account on Cisco IOS XE Wireless Controllers can be used to delete any user account, including administrator ones, due to weak access control in that web interface.
Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Denial of Service Vulnerabilities
Five separate flaws in the AnyConnect VPN server on Meraki MX and Z series gateways let an unauthenticated attacker drop existing SSL VPN sessions and block new ones from connecting.
Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Session Takeover and Denial of Service Vulnerability
Weak randomness and a race condition in the AnyConnect VPN server on Meraki MX and Z Series gateways let an unauthenticated attacker guess an authentication handler and hijack or crash someone else’s VPN session.