NDFC fails to properly validate SSH host keys for the switches and controllers it manages, letting an unauthenticated attacker sit between NDFC and a managed device to intercept traffic and capture credentials.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Secure Network Analytics Manager API Authorization Vulnerability
A low-privileged authenticated user can abuse an under-protected API in Cisco Secure Network Analytics Manager to fabricate findings, letting them mask real alerts or trigger false ones.
Cisco Secure Network Analytics Manager Privilege Escalation Vulnerability
An authenticated administrator on Cisco Secure Network Analytics Manager or its virtual variant can send crafted input to the web management interface and run arbitrary commands as root on the host OS.
Cisco Unified Communications Products Command Injection Vulnerability
An authenticated administrator on the CLI of several Cisco Unified Communications products can inject commands that run as root on the underlying OS, with no workaround and only patching to fix it.
Cisco Unified Communications Products Privilege Escalation Vulnerability
An authenticated local attacker with hypervisor admin rights can abuse over-permissioned system commands on Cisco’s Unified Communications and Contact Center virtual appliances to gain root on the guest OS.
Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control Vulnerability
An unauthenticated attacker who can reach the Cloud Connect port on Cisco Unified CCE can send crafted TCP traffic to read or alter data on the device, with no workaround available.
Cisco Unified Intelligence Center Privilege Escalation Vulnerabilities
Two flaws in Cisco Unified Intelligence Center let anyone already logged in with a low-privilege account reach reporting data and functions meant for other roles, affecting every contact-centre product that bundles the tool.
Cisco Unified Intelligent Contact Management Enterprise Cross-Site Scripting Vulnerability
A reflected cross-site scripting flaw in the admin web interface of Cisco Unified ICM Enterprise lets an attacker run script in a user’s browser via a crafted link, with no workaround yet available.
Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability
A flaw in Cisco Webex Meetings’ client join services let unauthenticated attackers manipulate cached HTTP responses, though Cisco has already fixed it on the cloud service with nothing for customers to patch.
Cisco Webex Services Cross-Site Scripting Vulnerabilities
Three flaws in Cisco’s cloud-based Webex service let a crafted link inject scripting into a user’s session, with the fix applied server-side and no local patching needed.