Management ACLs on Cisco IOS XR routers don’t actually block SSH, NetConf or gRPC because Packet I/O handles these features in Linux without enforcing the configured filter.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability
Cisco EPNM’s web management interface fails to properly validate uploaded files, letting anyone with valid Config Managers credentials plant arbitrary files via a specific API endpoint.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
A flaw in the web management API of Cisco EPNM and Prime Infrastructure lets any logged-in, low-privileged user pull configuration data they shouldn’t be able to see.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
An admin-level user can plant malicious script in the EPNM or Prime Infrastructure web interface, which then runs in the browser of anyone else who views that data field.
Cisco Unified Communications Manager IM & Presence Service Cross-Site Scripting Vulnerability
A stored input-validation flaw in the Unified CM IM&P admin web interface lets an attacker who tricks a user into clicking a crafted link run script in that page and read browser-based session data.
Cisco Webex Meetings URL Redirection Vulnerability
Cisco Webex Meetings failed to properly validate URLs in meeting-join links, letting an unauthenticated attacker craft links that send users to an untrusted site instead of the genuine Webex page.
Cisco Webex Meetings Cross-Site Scripting Vulnerability
An authenticated attacker could craft a malicious link that, once clicked, runs script in a victim’s Webex Meetings session via the user profile component, thanks to weak input validation.
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
A missing CSRF check in Unified Communications Manager’s web admin interface means a logged-in user who clicks a crafted link could unwittingly let an attacker carry out actions in their account, including admin-level call manager changes.
Cisco Nexus Dashboard Path Traversal Vulnerability
An authenticated administrator can restore a deliberately crafted backup file on Cisco Nexus Dashboard and use a path traversal flaw in the restore process to gain root on the device.
Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities
Missing authorization checks in the REST API of Nexus Dashboard and NDFC let a low-privileged authenticated user view sensitive data or perform limited admin actions like uploading images, with no workaround available.