PatchSiren

Cisco CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Cisco CVE published 2026-02-25

CVE-2026-20127

CVE-2026-20127 is a Cisco Catalyst SD-WAN Controller and Manager authentication bypass vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-25. CISA set a remediation due date of 2026-02-27 and pointed defenders to Emergency Directive 26-03 and Cisco’s hunt-and-hardening guidance, so exposed environments should be treated as time-sensitive.

Known exploited Cisco CVE published 2026-02-25

CVE-2022-20775

CVE-2022-20775 is a Cisco SD-WAN path traversal vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2026-02-25, with a mitigation due date of 2026-02-27. Because the supplied source corpus is limited to catalog and record metadata, this brief focuses on defensive prioritization: confirm whether any Cisco SD-WAN devices are exposed, follow Cisco’s official advisory and CISA’s Em [truncated]

MEDIUM Cisco CVE published 2026-02-04

CVE-2026-20123

A vulnerability exists in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This vulnerability could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is caused by improper input validation of parameters in HTTP requests. An attacker could exploit this by intercepting and modifying u [truncated]

MEDIUM Cisco CVE published 2026-02-04

CVE-2026-20111

CVE-2026-20111 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Prime Infrastructure. An authenticated, remote attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface, allowing the execution of arbitrary script code in the context of the affected interface or access to sensitive, browser-based infor [truncated]

Known exploited Cisco CVE published 2026-01-21

CVE-2026-20045

CVE-2026-20045 is a Cisco Unified Communications Products code injection vulnerability affecting Cisco Unified Communications Manager and listed by CISA in the Known Exploited Vulnerabilities (KEV) catalog. Because it is already in KEV, this should be treated as a high-priority remediation item. The supplied corpus does not include CVSS data or deeper technical detail, so the safest response is to invento [truncated]

Known exploited Cisco CVE published 2025-12-17

CVE-2025-20393

CVE-2025-20393 is a Cisco Multiple Products improper input validation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-12-17. Because it is a KEV-listed issue, defenders should treat it as actively exploited or otherwise confirmed by CISA as requiring prompt remediation. The supplied corpus does not identify the exact affected Cisco products or versions, so exposure ass [truncated]

Known exploited Cisco CVE published 2025-09-25

CVE-2025-20362

CVE-2025-20362 is a Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) missing authorization vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-25, which indicates known exploitation and makes it an urgent remediation item. For U.S. federal agencies, the KEV due date is 2025-09-26, tied to Emergency Directive 25-03 and the a [truncated]

Known exploited Cisco CVE published 2025-09-25

CVE-2025-20333

CVE-2025-20333 affects Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) and is described by CISA as a buffer overflow vulnerability. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2025-09-25 and set a due date of 2025-09-26 for federal agencies to begin following the required mitigation guidance. Because the vulnerability is in KEV, d [truncated]

Known exploited Cisco CVE published 2025-09-24

CVE-2025-20352

CVE-2025-20352 affects Cisco IOS and IOS XE software and is listed by CISA in the Known Exploited Vulnerabilities catalog. The supplied title identifies the issue as an SNMP vulnerability that can lead to denial of service or remote code execution, so exposed Cisco network devices should be treated as urgent remediation candidates.

Known exploited Cisco CVE published 2025-07-28

CVE-2025-20337

CVE-2025-20337 is a Cisco Identity Services Engine injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-07-28. The public record in this corpus does not include a CVSS score or deeper technical exploitation detail, so the strongest defensive signal is its KEV status and the required remediation deadline of 2025-08-18.

Known exploited Cisco CVE published 2025-07-28

CVE-2025-20281

CVE-2025-20281 is a Cisco Identity Services Engine injection vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2025-07-28. Because it is a KEV-listed issue, affected Cisco ISE deployments should be treated as urgent remediation targets. The supplied corpus does not include a CVSS score or detailed impact analysis, so defensive action should be driven by Cisco guidance and exp [truncated]

HIGH Cisco CVE published 2025-04-07

CVE-2023-20032

CVE-2023-20032 appears in the 2025-04-07 CISA CSAF advisory for ABB M2M Gateway products, including ARM600 and ABB M2M Gateway SW. The source record describes a missing buffer size check that can lead to a heap buffer overflow write, and recommends reducing external exposure, using VPN/DMZ controls, allowlisting, credential hardening, and continuous monitoring. The supplied corpus also contains an importa [truncated]

Known exploited Cisco CVE published 2025-03-31

CVE-2024-20439

CVE-2024-20439 is a Cisco Smart Licensing Utility static credential vulnerability that CISA added to the Known Exploited Vulnerabilities catalog. Because it is a KEV-listed issue, defenders should treat it as urgent and follow Cisco’s mitigation guidance or discontinue use if mitigation is not available.

Known exploited Cisco CVE published 2025-03-03

CVE-2023-20118

CVE-2023-20118 is a Cisco Small Business RV Series Routers command injection vulnerability that CISA added to its Known Exploited Vulnerabilities (KEV) catalog on 2025-03-03. KEV inclusion means CISA has confirmed known exploitation and set a remediation due date of 2025-03-24. The supplied source metadata does not provide a CVSS score, so prioritization here is driven by KEV status and the affected produ [truncated]

Known exploited Cisco CVE published 2024-11-12

CVE-2014-2120

CVE-2014-2120 is a Cisco Adaptive Security Appliance (ASA) cross-site scripting (XSS) vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is operational urgency: CISA’s record directs organizations to apply mitigations per Cisco’s instructions or discontinue use of the product if mitigations are unavailable.

Known exploited Cisco CVE published 2024-10-24

CVE-2024-20481

CVE-2024-20481 is a Cisco ASA and Firepower Threat Defense denial-of-service vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. That KEV listing makes this a priority for defenders because it is treated as actively exploited. The supplied corpus does not include affected versions, attack preconditions, or a CVSS score, so remediation should follow Cisco’s official guidance a [truncated]

Known exploited Cisco CVE published 2024-07-02

CVE-2024-20399

CVE-2024-20399 is a Cisco NX-OS command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-02. That KEV listing means defenders should treat it as urgently actionable, even though the supplied corpus does not include a CVSS score or the full vendor-advisory technical details. Cisco’s official advisory and the NVD entry are the primary public references in the [truncated]

Known exploited Cisco CVE published 2024-04-24

CVE-2024-20359

CVE-2024-20359 is a Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-04-24. Because it is listed in KEV, defenders should treat it as actively exploited or otherwise confirmed in the wild and prioritize remediation quickly. CISA’s required action is to apply mitigations per v [truncated]

Known exploited Cisco CVE published 2024-04-24

CVE-2024-20353

CVE-2024-20353 is a Cisco ASA and Firepower Threat Defense (FTD) denial-of-service vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2024-04-24. Because it is a KEV-listed issue, defenders should treat it as operationally urgent and follow Cisco’s mitigation guidance or remove the product from use if mitigations are unavailable. The supplied corpus does not include deeper tec [truncated]

Known exploited Cisco CVE published 2024-02-15

CVE-2020-3259

CVE-2020-3259 is a Cisco ASA and Firepower Threat Defense information disclosure vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-15, and the KEV entry marks it as associated with known ransomware campaign use. For defenders, this makes the issue a priority even though the supplied corpus does not include full vendor advisory details or CVSS scoring.

Known exploited Cisco CVE published 2023-10-23

CVE-2023-20273

CVE-2023-20273 is a Cisco IOS XE Web UI command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-23, with a remediation due date of 2023-10-27. Because CISA placed it in KEV, defenders should treat it as an urgent exposure review item, especially for systems exposed to the internet or other untrusted networks.

Known exploited Cisco CVE published 2023-10-16

CVE-2023-20198

CVE-2023-20198 is a Cisco IOS XE Web UI privilege escalation issue that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-16. For defenders, the key signal is not just the vulnerability name, but the KEV status: CISA’s record requires organizations to verify compliance with BOD 23-02, apply vendor mitigations, and, for affected products exposed to the internet or untrusted networks, fol [truncated]

Known exploited Cisco CVE published 2023-10-10

CVE-2023-20109

CVE-2023-20109 is a Cisco IOS and IOS XE vulnerability affecting Group Encrypted Transport VPN (GETVPN). CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10, indicating it has been observed as exploited in the wild. The available official records emphasize defensive action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

Known exploited Cisco CVE published 2023-09-13

CVE-2023-20269

CVE-2023-20269 is a Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) unauthorized access vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2023-09-13. The supplied KEV metadata marks it as known exploited and notes known ransomware campaign use. Defenders should treat this as an urgent remediation item and follow Cisco’s mitigation guidance, includin [truncated]

Known exploited Cisco CVE published 2023-05-19

CVE-2016-6415

CVE-2016-6415 is a Cisco IKEv1 information disclosure vulnerability affecting Cisco IOS, IOS XR, and IOS XE. CISA has listed it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as actively important to remediate on any exposed or still-supported Cisco systems. The supplied source data does not provide deeper technical detail, so the safest response is to verify device [truncated]

Known exploited Cisco CVE published 2023-05-19

CVE-2004-1464

CVE-2004-1464 is a Cisco IOS denial-of-service vulnerability that appears in CISA’s Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat it as a real-world risk, even though the supplied record set does not include deeper technical detail or a CVSS score. The safest response is to follow Cisco’s update guidance, verify whether any IOS systems are exposed, and prioritize r [truncated]

Known exploited Cisco CVE published 2023-04-19

CVE-2017-6742

CVE-2017-6742 is identified in the supplied official records as a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-19 and set a remediation due date of 2023-05-10, which makes it a priority for defenders managing Cisco network infrastructure. The supplied corpus does not include affected-version details or explo [truncated]

Known exploited Cisco CVE published 2022-10-24

CVE-2020-3433

CVE-2020-3433 is a Cisco AnyConnect Secure Mobility Client for Windows DLL hijacking vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry indicates known exploitation and notes known ransomware campaign use, so defenders should treat this as a high-priority endpoint remediation item.

Known exploited Cisco CVE published 2022-10-24

CVE-2020-3153

CVE-2020-3153 is a Cisco AnyConnect Secure Mobility Client for Windows uncontrolled search path vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog and notes known ransomware campaign use, which makes it a high-priority issue for organizations that still have affected Windows installations.

Known exploited Cisco CVE published 2022-06-08

CVE-2019-15271

CVE-2019-15271 is a Cisco RV Series Routers deserialization of untrusted data vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it should be treated as an active defensive priority. The supplied record directs defenders to apply updates per vendor instructions.