An authenticated attacker with valid SNMP credentials can crash a Cisco IOS XE switch that has WRED for MPLS EXP configured, forcing an unexpected reload.
Posts tagged: Cisco
Cisco IOS XE Software Web UI Reflected Cross-Site Scripting Vulnerability
A reflected XSS bug in Cisco IOS XE’s Web Authentication feature lets an attacker who tricks a user into clicking a crafted link steal that user’s session cookies from the device’s web interface.
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controller for Cloud Unauthenticated Access to Certificate Enrollment Service Vulnerability
Leftover PKI server access on Catalyst 9800-CL virtual controllers lets an unauthenticated attacker request a certificate and join a rogue device to the wireless LAN controller.
Cisco IOS XE SD-WAN Software Packet Filtering Bypass Vulnerability
A crafted packet can slip past Layer 3/4 filters on Cisco IOS XE SD-WAN cEdge routers running Controller mode with SNMP enabled on an SD-WAN tunnel interface, letting an unauthenticated attacker inject traffic past those controls.
Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability
IOS XR devices with the management interface up can be knocked offline by an ARP flood on that interface, since Cisco’s LPTS protections don’t rate-limit management-plane traffic and there’s no workaround short of upgrading.
Cisco IOS XR Software Image Verification Bypass Vulnerability
A flaw in how Cisco IOS XR checks .iso install files lets someone who already has root-system access load unsigned software, quietly defeating the image signature check.
Cisco IOS XR Software Management Interface ACL Bypass Vulnerability
On several IOS XR platforms, ACLs applied to the management interface silently fail to restrict SSH, NETCONF or gRPC, so anyone who can reach that interface can reach those services regardless of the filter you configured.
Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability
An authenticated attacker holding Config Managers credentials on Cisco EPNM can push arbitrary files onto the system via a flawed API endpoint, with no workaround available short of upgrading to 8.1.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
A flaw in the web management API of Cisco EPNM and Prime Infrastructure lets any logged-in, low-privileged user pull configuration data they shouldn’t be able to see.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco EPNM and Prime Infrastructure lets an already-authenticated admin plant script in management interface data fields that later runs in another admin’s browser session.