Anyone holding valid VPN credentials can send crafted HTTP requests to the ASA/FTD VPN web server and gain root code execution, with no workaround to fall back on.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability
A flaw in the web services shared by Cisco ASA, FTD, IOS, IOS XE and IOS XR lets an attacker send crafted HTTP requests to run code as root, with ASA/FTD reachable without any login.
Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability
An unauthenticated attacker can send crafted HTTP requests to the VPN web server on Cisco ASA and FTD devices and reach restricted URL endpoints that should require login.
Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability
An unauthenticated attacker within radio range of a Cisco access point can forge 802.11 action frames to corrupt Device Analytics data for other clients on the same wireless controller.
Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability
Wireless clients can send crafted IPv6 router advertisements to trick Cisco access points using CAPWAP over IPv6 into flipping their gateway, causing intermittent packet loss for connected devices.
Cisco IOS XE Software for Catalyst 9000 Series Switches Denial of Service Vulnerability
A crafted Ethernet frame sent to a trunk, TrustSec or MACsec-enabled port on a Catalyst 9000 switch can jam the egress queue and stop all outbound traffic on that port, with no workaround and a reload the only fix.
Cisco IOS XE Software on Cisco Catalyst 9500X and 9600X Series Switches Virtual Interface Access Control List Bypass Vulnerability
On Catalyst 9500X and 9600X switches, flooding an SVI with traffic from an unlearned MAC address can overwhelm the MAC address table and let traffic slip past an egress ACL without any authentication.
Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability
An unauthenticated attacker can send crafted IPv4 traffic to a Cisco vEdge router interface and slip past a configured ACL because the implicit deny-all at its end isn’t properly enforced.
Cisco IOS and IOS XE Software CLI Denial of Service Vulnerability
A CLI buffer overflow lets a logged-in, low-privileged user on Cisco IOS or IOS XE crash and reload the device, but only if an admin has enabled the non-default ‘shell processing full’ command.
Cisco IOS Software Industrial Ethernet Switch Device Manager Denial of Service Vulnerability
A low-privileged authenticated user can crash Cisco Industrial Ethernet switches by sending a crafted URL to the web-based device manager, forcing an unplanned reload.