Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to issue commands on the underlying …
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability
An authenticated but low-privileged user can send a crafted request to a Prime Infrastructure or EPNM REST API to pull data out of backend database tables via blind SQL injection.
Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
An authenticated attacker holding at least Report Designer access to Cisco Unified Intelligence Center can upload arbitrary files through the web management interface and potentially escalate to root.
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Three maximum-severity flaws let anyone reach Cisco ISE’s APIs without logging in and run commands as root, with one variant also allowing arbitrary file uploads into privileged directories.
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
Flaws in the SNMP subsystem of Cisco IOS and IOS XE let anyone with a read-only community string or valid SNMPv3 credentials send a crafted packet to execute code or reload the device.