An administrator already logged into a Cisco IOS XE device can pass crafted arguments to CLI commands to break out and run commands as root on the underlying operating system.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
Malformed CAPWAP packets processed by NBAR on Cisco IOS XE routers can crash the device remotely with no login required, forcing an unexpected reload.
Cisco IOS XE Software Secure Boot Bypass Vulnerabilities
A flaw in how Cisco IOS XE validates software packages lets a local authenticated attacker or someone with physical device access plant a crafted file that survives reboot and undermines secure boot’s chain of trust.
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
A stack overflow in the SNMP subsystem of Cisco IOS and IOS XE lets someone with valid SNMPv2c or SNMPv3 credentials crash the device or run code as root.
Cisco IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability
Authenticated SNMP requests to Cisco IOS XE switches configured with WRED for MPLS can trigger improper error handling that forces an unexpected device reload.
Cisco IOS XE Software Web UI Reflected Cross-Site Scripting Vulnerability
A reflected XSS flaw in the Cisco IOS XE web UI lets an attacker craft a malicious link that, once clicked by an administrator, can steal that admin’s device session cookie.
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controller for Cloud Unauthenticated Access to Certificate Enrollment Service Vulnerability
Leftover Day One setup residue on Catalyst 9800 Series Cloud wireless controllers leaves the PKI server reachable without authentication, letting a remote attacker request a certificate and enrol a rogue device.
Cisco IOS XE SD-WAN Software Packet Filtering Bypass Vulnerability
Cisco IOS XE SD-WAN devices with SNMP enabled on an SD-WAN tunnel interface can have their Layer 3/4 traffic filters bypassed by a crafted packet, letting unauthenticated remote attackers push packets through that should be blocked.
Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability
An unauthenticated attacker on the same network segment can flood a Cisco IOS XR device’s management interface with ARP traffic, causing a broadcast storm that degrades or knocks out management access.
Cisco IOS XR Software Image Verification Bypass Vulnerability
A root-privileged local attacker on Cisco IOS XR devices can tamper with an .iso installation file to slip past signature checks and boot unsigned software, undermining trust in the platform’s own integrity checks.