An unauthenticated attacker can send crafted HTTP requests to the VPN web server on Cisco ASA and FTD devices and reach restricted URL endpoints that should require login.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability
An unauthenticated attacker within radio range of a Cisco access point can forge 802.11 action frames to corrupt Device Analytics data for other clients on the same wireless controller.
Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability
A wireless client can send crafted IPv6 router advertisement packets to a Cisco access point and cause it to swap its IPv6 gateway, breaking connectivity for other associated clients.
Cisco IOS XE Software for Catalyst 9000 Series Switches Denial of Service Vulnerability
Crafted Ethernet frames sent from the local network can silently kill outbound traffic on a Catalyst 9000 switch port, with no workaround and only a software fix available.
Cisco IOS XE Software on Cisco Catalyst 9500X and 9600X Series Switches Virtual Interface Access Control List Bypass Vulnerability
On Catalyst 9500X and 9600X switches, flooding an SVI with traffic from an unlearned MAC address can overwhelm the MAC address table and let traffic slip past an egress ACL without any authentication.
Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability
A flaw in how Cisco SD-WAN vEdge devices enforce the implicit deny at the end of an ACL lets unauthenticated attackers push traffic past interface access controls that should have blocked it.
Cisco IOS and IOS XE Software CLI Denial of Service Vulnerability
Devices running Cisco IOS or IOS XE with the shell processing full command enabled can be crashed by an authenticated local user issuing crafted CLI commands that trigger a buffer overflow.
Cisco IOS Software Industrial Ethernet Switch Device Manager Denial of Service Vulnerability
An authenticated low-privilege user can send a crafted URL to the web-based device manager on Cisco Industrial Ethernet switches and force the switch to reload, dropping network connectivity until it restarts.
Cisco IOS and IOS XE Software TACACS+ Authentication Bypass Vulnerability
Cisco IOS and IOS XE devices that use TACACS+ without a configured shared secret can have their authentication messages intercepted or spoofed, letting an unauthenticated attacker bypass login controls.
Cisco IOS XE Software HTTP API Command Injection Vulnerability
A command injection bug in Cisco IOS XE’s HTTP API lets an admin-privileged attacker, or one who tricks an admin into clicking a link, run commands as root, with no workaround available.