On Catalyst 9500X and 9600X switches, flooding an SVI with traffic from an unlearned MAC address can overwhelm the MAC address table and let traffic slip past an egress ACL without any authentication.
Posts tagged: Cisco
Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability
An unauthenticated attacker can send crafted IPv4 traffic to a Cisco vEdge router interface and slip past a configured ACL because the implicit deny-all at its end isn’t properly enforced.
Cisco IOS and IOS XE Software CLI Denial of Service Vulnerability
A CLI buffer overflow lets a logged-in, low-privileged user on Cisco IOS or IOS XE crash and reload the device, but only if an admin has enabled the non-default ‘shell processing full’ command.
Cisco IOS Software Industrial Ethernet Switch Device Manager Denial of Service Vulnerability
A low-privileged authenticated user can crash Cisco Industrial Ethernet switches by sending a crafted URL to the web-based device manager, forcing an unplanned reload.
Cisco IOS and IOS XE Software TACACS+ Authentication Bypass Vulnerability
Cisco IOS and IOS XE devices configured for TACACS+ without a shared secret on every server can let a network-positioned attacker read authentication traffic or impersonate the TACACS+ server to bypass login.
Cisco IOS XE Software HTTP API Command Injection Vulnerability
A flaw in the HTTP API of Cisco IOS XE lets an authenticated admin, or an admin tricked into clicking a crafted link, trigger root-level command execution on the device.
Cisco IOS XE Software CLI Argument Injection Vulnerability
An admin already logged into an IOS XE device’s CLI can pass crafted arguments to certain commands and escalate from level-15 access to root on the underlying OS.
Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
An unauthenticated attacker can crash affected Cisco IOS XE routers and edge platforms by sending malformed CAPWAP packets, but only where NBAR’s CAPWAP inspection feature is turned on.
Cisco IOS XE Software Secure Boot Bypass Vulnerabilities
Two IOS XE flaws let a privilege-15 admin or someone with physical device access plant a crafted file that boots as trusted code, permanently breaking secure boot’s chain of trust.
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
A stack overflow in Cisco IOS and IOS XE’s SNMP subsystem lets an authenticated attacker with admin credentials trigger a device reload or, on IOS XE, execute code as root via a crafted SNMP packet.