PatchSiren

Cisco CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Cisco CVE published 2022-05-24

CVE-2016-6367

CVE-2016-6367 is a Cisco Adaptive Security Appliance (ASA) CLI remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV inclusion means defenders should treat it as a known-exploited issue and prioritize vendor-guided remediation. The available official sources provided here do not include exploitable details, but they do confirm the vulnerability n [truncated]

Known exploited Cisco CVE published 2022-05-24

CVE-2016-6366

CVE-2016-6366 is a Cisco Adaptive Security Appliance (ASA) SNMP buffer overflow vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because CISA marked it as known to be exploited in the wild, organizations should treat Cisco ASA devices as a priority for review, patching, and exposure reduction.

Known exploited Cisco CVE published 2022-05-23

CVE-2022-20821

CVE-2022-20821 is identified by CISA as the "Cisco IOS XR Open Port Vulnerability" and was added to the Known Exploited Vulnerabilities catalog on 2022-05-23. CISA’s record directs organizations to apply updates per vendor instructions, with a remediation due date of 2022-06-13. The source corpus does not include a vendor advisory or deeper technical write-up, so this debrief is limited to the official CV [truncated]

Known exploited Cisco CVE published 2022-03-25

CVE-2018-0147

CVE-2018-0147 is identified in the supplied official records as a Java deserialization vulnerability affecting Cisco Secure Access Control System (ACS). CISA has added it to the Known Exploited Vulnerabilities catalog, which means it is treated as a known exploitation risk rather than a purely theoretical issue. The KEV entry directs organizations to apply updates per vendor instructions, so any active Ci [truncated]

Known exploited Cisco CVE published 2022-03-25

CVE-2018-0125

CVE-2018-0125 is a Cisco VPN Routers remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the important signal is not just the vulnerability type, but the fact that it is treated as known exploited and comes with a remediation deadline in the KEV entry.

Known exploited Cisco CVE published 2022-03-25

CVE-2017-3881

CVE-2017-3881 is identified in the supplied official records as a remote code execution vulnerability affecting Cisco IOS and IOS XE. CISA has listed it in the Known Exploited Vulnerabilities catalog, which makes it a high-priority remediation item for any organization running the affected Cisco platform family. The supplied metadata directs defenders to apply vendor updates per Cisco instructions, with a [truncated]

Known exploited Cisco CVE published 2022-03-25

CVE-2015-0666

CVE-2015-0666 affects Cisco Prime Data Center Network Manager (DCNM) and is described as a directory traversal vulnerability. It is listed in CISA’s Known Exploited Vulnerabilities catalog, which means defenders should treat it as an active risk and prioritize remediation. CISA’s entry directs organizations to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-25

CVE-2010-3035

CVE-2010-3035 is a Cisco IOS XR Border Gateway Protocol (BGP) denial-of-service vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-25. Because it is in KEV, it should be treated as a prioritized remediation item for any environment running affected Cisco IOS XR systems. CISA’s listed required action is to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-25

CVE-2009-2055

CVE-2009-2055 is a Cisco IOS XR Border Gateway Protocol (BGP) denial-of-service vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is that this issue is treated as actively exploited and should be prioritized for remediation using Cisco’s vendor guidance.

Known exploited Cisco CVE published 2022-03-03

CVE-2022-20708

CVE-2022-20708 is a Cisco Small Business RV Series router vulnerability described as a stack-based buffer overflow affecting RV160, RV260, RV340, and RV345 series devices. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2022-03-03, which indicates active exploitation or evidence of exploitation significant enough to require prioritized remediation. Organizations using the affected router [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2022-20703

CVE-2022-20703 is a Cisco Small Business RV Series Routers stack-based buffer overflow vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as an actively exploited issue and prioritize remediation on affected RV160, RV260, RV340, and RV345 Series Routers.

Known exploited Cisco CVE published 2022-03-03

CVE-2022-20701

CVE-2022-20701 is a Cisco Small Business RV Series Routers stack-based buffer overflow vulnerability affecting the RV160, RV260, RV340, and RV345 series. In the supplied official records, CISA lists it as a Known Exploited Vulnerability and directs defenders to apply updates per vendor instructions. CISA added the item on 2022-03-03 and set a remediation due date of 2022-03-17.

Known exploited Cisco CVE published 2022-03-03

CVE-2022-20700

CVE-2022-20700 is a stack-based buffer overflow affecting Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. CISA listed it in the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a remediation due date of 2022-03-17, so organizations using these routers should treat it as an urgent patching item.

Known exploited Cisco CVE published 2022-03-03

CVE-2022-20699

CVE-2022-20699 affects Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers and is described as a stack-based buffer overflow vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, which makes it a high-priority issue for any organization using the affected router family. The available official guidance is to apply updates per the vendor’s instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2019-1652

CVE-2019-1652 is a Cisco Small Business router vulnerability involving improper input validation in the RV320 and RV325 Dual Gigabit WAN VPN Routers. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it has been flagged as actively exploited or otherwise confirmed to be a real-world risk. For defenders, this is an urgent patch-and-review item for any environment that still operates [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0180

CVE-2018-0180 is a Cisco IOS Software denial-of-service vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, which means it is treated as a known exploited issue and should be prioritized for remediation. The supplied records do not include exploit mechanics or CVSS scoring, but they do direct defenders to apply vendor updates.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0179

CVE-2018-0179 is a Cisco IOS Software denial-of-service vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-03. Because it is in KEV, defenders should treat it as a priority patching item and follow Cisco’s update guidance without delay.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0175

CVE-2018-0175 is a Cisco IOS, XR, and XE Software buffer overflow vulnerability that CISA lists in the Known Exploited Vulnerabilities (KEV) catalog. In the supplied KEV record, the required action is to apply updates per vendor instructions, with a due date of 2022-03-17. Organizations running Cisco network infrastructure should treat this as an urgent remediation item and confirm whether any IOS, IOS XR [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0174

CVE-2018-0174 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. That KEV listing is an important defensive signal: even without a CVSS score in the supplied data, the vulnerability is considered actively exploited or at least known to be exploited, so Cisco device owners should treat remediation as urgent.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0173

CVE-2018-0173 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The key defensive takeaway is straightforward: treat this as a high-priority remediation item and apply Cisco-recommended updates as soon as possible.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0172

CVE-2018-0172 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat affected Cisco network devices as a priority for inventory, patching, and validation against Cisco guidance.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0167

CVE-2018-0167 is a Cisco IOS, XR, and XE Software buffer overflow vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because KEV inclusion indicates observed exploitation, organizations running Cisco IOS, XR, or XE should treat remediation as urgent and follow Cisco’s update guidance.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0161

CVE-2018-0161 is a Cisco IOS Software vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied record identifies it as a Cisco IOS Software resource management errors issue and directs defenders to apply updates per vendor instructions. Because it appears in the KEV catalog, it should be treated as a confirmed exploitation risk rather than a theoretical issue.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0159

CVE-2018-0159 is a Cisco IOS Software and Cisco IOS XE Software denial-of-service vulnerability affecting Internet Key Exchange version 1 (IKEv1). CISA includes it in the Known Exploited Vulnerabilities catalog, which means it should be treated as a remediation priority for environments running the affected Cisco platforms. The supplied CISA record directs teams to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0158

CVE-2018-0158 is a Cisco IOS Software and Cisco IOS XE Software Internet Key Exchange memory leak vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation and a required remediation window by 2022-03-17. The official guidance in the supplied corpus is to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0156

CVE-2018-0156 is a Cisco IOS Software and Cisco IOS XE Software Smart Install denial-of-service vulnerability. CISA has included it in the Known Exploited Vulnerabilities (KEV) catalog, which means defenders should treat it as actively important to address. The KEV entry directs organizations to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0155

CVE-2018-0155 is a Cisco Catalyst Bidirectional Forwarding Detection (BFD) denial-of-service vulnerability affecting Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches. In the supplied records, CISA lists the issue in its Known Exploited Vulnerabilities catalog, so it should be treated as a high-priority remediation item. The source corpus does not provide CVSS scoring or exploi [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0154

CVE-2018-0154 is a Cisco IOS Software denial-of-service issue affecting the Integrated Services Module for VPN. CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as actively exploited and prioritize remediation on exposed Cisco IOS systems.

Known exploited Cisco CVE published 2022-03-03

CVE-2018-0151

CVE-2018-0151 is a Cisco IOS and IOS XE Software vulnerability affecting Quality of Service functionality and described as a remote code execution issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating it has been observed as exploited in the wild. The defensive takeaway is straightforward: prioritize vendor-recommended updates on affected Cisco network devices.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6744

CVE-2017-6744 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Cisco IOS software SNMP remote code execution issue. Because it appears in KEV, defenders should treat it as actively important and prioritize remediation using vendor guidance.