Cisco’s Unified Communications Manager admin web interface lacks proper CSRF protection, letting an attacker trick a logged-in administrator into unknowingly executing actions on the call-management system.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Nexus Dashboard Path Traversal Vulnerability
An admin-only backup restore flaw in Cisco Nexus Dashboard lets someone with valid Administrator credentials plant a crafted backup file that escalates them to root on the underlying host.
Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities
Missing authorisation checks on some Nexus Dashboard and NDFC REST API endpoints let a low-privileged, authenticated user read proxy and NTP settings and tamper with image files, with no workaround available.
Cisco NX-OS Software Command Injection Vulnerability
An authenticated CLI user on Cisco NX-OS switches and fabric interconnects can inject crafted command arguments to read and write OS files, limited to whatever permissions their non-root account already has.
Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability
Cisco NX-OS logs can capture stored credentials in plain text, letting anyone with local file-system access on Nexus or UCS gear read them straight out of the logs.
Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability
An authenticated low-privileged attacker who can reach NX-API, NETCONF, RESTCONF, gRPC or telemetry on a Nexus 3000/9000 switch can crash the PIM6 process, disrupting multicast routing until it restarts.
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Stored Cross-Site Scripting Vulnerability
A stored XSS flaw in Cisco IMC’s virtual keyboard/video monitor interface lets a low-privileged, already-authenticated user plant script that runs in another vKVM user’s session, and the same client ships inside a long list of UCS-based appliances.
Cisco UCS Manager Software Command Injection Vulnerabilities
Two command injection bugs in Cisco UCS Manager let an already-authenticated admin escalate to root or tamper with system files on the fabric interconnect’s underlying OS.
Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability
An open redirect in the vKVM component of Cisco IMC and UCS Manager lets an attacker lure an admin into clicking a link that redirects their session to a credential-harvesting page.
Cisco UCS Manager Software Stored Cross-Site Scripting Vulnerability
A stored XSS flaw in Cisco UCS Manager’s web interface lets an Administrator or AAA Administrator plant script that runs in another admin’s browser session on the fabric interconnect.