An authenticated CLI user on affected Cisco NX-OS switches and fabric interconnects can inject commands to read and write files at the underlying OS level, with no workaround available.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
Cisco NX-OS logs can capture stored credentials in plain text, letting anyone with local file-system access on Nexus or UCS gear read them straight out of the logs.
Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability
Authenticated attackers on Nexus 3000/9000 switches can crash the PIM6 process via a crafted ephemeral query sent over NX-API, NETCONF, RESTCONF, gRPC or telemetry, disrupting IPv6 multicast routing.
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Stored Cross-Site Scripting Vulnerability
An authenticated user with low privileges can plant a stored script in Cisco IMC’s virtual keyboard/monitor interface, which then runs in the browser session of anyone who views it, with no workaround available.
Cisco UCS Manager Software Command Injection Vulnerabilities
Admin users on Cisco UCS Manager’s CLI or web interface can inject commands that escalate to root on the fabric interconnects managing the whole UCS chassis, with no workaround available.
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
An unauthenticated attacker can craft a link that abuses the Cisco IMC virtual keyboard-video-monitor connection to redirect an administrator to a malicious site capable of harvesting their login credentials.
Cisco UCS Manager Software Stored Cross-Site Scripting Vulnerability
An authenticated Administrator or AAA Administrator on Cisco UCS Manager’s web interface can plant a stored XSS payload that runs in the browser of anyone who later views the affected page.
Cisco Nexus 3000 and 9000 Series Switches Intermediate System-to-Intermediate System Denial of Service Vulnerability
An unauthenticated attacker with Layer 2 access to a Nexus 3000 or 9000 switch can send a malformed IS-IS packet to crash the IS-IS process and force a device reload.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Sensitive Information Disclosure Vulnerability
A path-traversal flaw in the web interface of Cisco EPNM and Prime Infrastructure lets an authenticated, low-privileged user pull arbitrary files off the underlying server filesystem.
Cisco Duo Authentication Proxy Information Disclosure Vulnerability
Debug logging in Cisco Duo Authentication Proxy fails to mask sensitive data properly, letting someone with high-level access read secrets straight out of the log files.