An authenticated Cisco ISE administrator can upload arbitrary files through the management GUI’s file copy function, a flaw fixed in newer patch releases with no workaround available.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
A buffer overflow in the Smart Install feature of Cisco IOS and IOS XE lets an unauthenticated attacker crash or fully take over switches and routers, and Smart Install is on by default on affected gear.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Web Services Denial of Service Vulnerability
An unauthenticated attacker can send a single crafted HTTP request to the web services interface on Cisco ASA or FTD and force the firewall to reload, with no workaround to fall back on.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability
On Cisco ASA and FTD firewalls with a loopback interface configured, traffic that access control rules should block can reach that interface anyway, letting an unauthenticated remote attacker slip past the filter.
Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities
Six flaws in IKEv2 VPN handling on Cisco IOS, IOS XE, ASA and FTD let an unauthenticated attacker crash the device or leak memory until it fails, with no workaround short of patching.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities
Admin-level users on Cisco ASA and FTD firewalls can inject commands that run as root on the underlying OS, turning a valid admin login into full device compromise.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability
A flaw in the DHCP client on Cisco ASA and FTD firewalls lets an adjacent, unauthenticated attacker send crafted DHCPv4 packets that exhaust device memory and force a manual reboot.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability
An authenticated VPN user can send crafted HTTP requests to the SSL VPN web server on Cisco ASA and FTD, creating or deleting operating system files and potentially forcing a reboot to restore VPN service.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability
A DNS inspection bug in Cisco ASA and FTD firewalls lets an unauthenticated attacker crash the device with crafted DNS packets whenever NAT and DNS inspection are both enabled.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL/TLS Certificate Denial of Service Vulnerability
A crafted SSL/TLS certificate sent to Cisco ASA or FTD firewalls can force an unexpected reload, letting an unauthenticated remote attacker knock out the firewall with no workaround available.