These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2016-6367 is a Cisco Adaptive Security Appliance (ASA) CLI remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV inclusion means defenders should treat it as a known-exploited issue and prioritize vendor-guided remediation. The available official sources provided here do not include exploitable details, but they do confirm the vulnerability n [truncated]
CVE-2016-6366 is a Cisco Adaptive Security Appliance (ASA) SNMP buffer overflow vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because CISA marked it as known to be exploited in the wild, organizations should treat Cisco ASA devices as a priority for review, patching, and exposure reduction.
CVE-2022-20821 is identified by CISA as the "Cisco IOS XR Open Port Vulnerability" and was added to the Known Exploited Vulnerabilities catalog on 2022-05-23. CISA’s record directs organizations to apply updates per vendor instructions, with a remediation due date of 2022-06-13. The source corpus does not include a vendor advisory or deeper technical write-up, so this debrief is limited to the official CV [truncated]
CVE-2018-0147 is identified in the supplied official records as a Java deserialization vulnerability affecting Cisco Secure Access Control System (ACS). CISA has added it to the Known Exploited Vulnerabilities catalog, which means it is treated as a known exploitation risk rather than a purely theoretical issue. The KEV entry directs organizations to apply updates per vendor instructions, so any active Ci [truncated]
CVE-2018-0125 is a Cisco VPN Routers remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the important signal is not just the vulnerability type, but the fact that it is treated as known exploited and comes with a remediation deadline in the KEV entry.
CVE-2017-3881 is identified in the supplied official records as a remote code execution vulnerability affecting Cisco IOS and IOS XE. CISA has listed it in the Known Exploited Vulnerabilities catalog, which makes it a high-priority remediation item for any organization running the affected Cisco platform family. The supplied metadata directs defenders to apply vendor updates per Cisco instructions, with a [truncated]
CVE-2015-0666 affects Cisco Prime Data Center Network Manager (DCNM) and is described as a directory traversal vulnerability. It is listed in CISA’s Known Exploited Vulnerabilities catalog, which means defenders should treat it as an active risk and prioritize remediation. CISA’s entry directs organizations to apply updates per vendor instructions.
CVE-2010-3035 is a Cisco IOS XR Border Gateway Protocol (BGP) denial-of-service vulnerability that CISA added to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-25. Because it is in KEV, it should be treated as a prioritized remediation item for any environment running affected Cisco IOS XR systems. CISA’s listed required action is to apply updates per vendor instructions.
CVE-2009-2055 is a Cisco IOS XR Border Gateway Protocol (BGP) denial-of-service vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is that this issue is treated as actively exploited and should be prioritized for remediation using Cisco’s vendor guidance.
CVE-2022-20708 is a Cisco Small Business RV Series router vulnerability described as a stack-based buffer overflow affecting RV160, RV260, RV340, and RV345 series devices. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2022-03-03, which indicates active exploitation or evidence of exploitation significant enough to require prioritized remediation. Organizations using the affected router [truncated]
CVE-2022-20703 is a Cisco Small Business RV Series Routers stack-based buffer overflow vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as an actively exploited issue and prioritize remediation on affected RV160, RV260, RV340, and RV345 Series Routers.
CVE-2022-20701 is a Cisco Small Business RV Series Routers stack-based buffer overflow vulnerability affecting the RV160, RV260, RV340, and RV345 series. In the supplied official records, CISA lists it as a Known Exploited Vulnerability and directs defenders to apply updates per vendor instructions. CISA added the item on 2022-03-03 and set a remediation due date of 2022-03-17.
CVE-2022-20700 is a stack-based buffer overflow affecting Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers. CISA listed it in the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a remediation due date of 2022-03-17, so organizations using these routers should treat it as an urgent patching item.
CVE-2022-20699 affects Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers and is described as a stack-based buffer overflow vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, which makes it a high-priority issue for any organization using the affected router family. The available official guidance is to apply updates per the vendor’s instructions.
CVE-2019-1652 is a Cisco Small Business router vulnerability involving improper input validation in the RV320 and RV325 Dual Gigabit WAN VPN Routers. CISA lists it in the Known Exploited Vulnerabilities catalog, which means it has been flagged as actively exploited or otherwise confirmed to be a real-world risk. For defenders, this is an urgent patch-and-review item for any environment that still operates [truncated]
CVE-2018-0180 is a Cisco IOS Software denial-of-service vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, which means it is treated as a known exploited issue and should be prioritized for remediation. The supplied records do not include exploit mechanics or CVSS scoring, but they do direct defenders to apply vendor updates.
CVE-2018-0179 is a Cisco IOS Software denial-of-service vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-03. Because it is in KEV, defenders should treat it as a priority patching item and follow Cisco’s update guidance without delay.
CVE-2018-0175 is a Cisco IOS, XR, and XE Software buffer overflow vulnerability that CISA lists in the Known Exploited Vulnerabilities (KEV) catalog. In the supplied KEV record, the required action is to apply updates per vendor instructions, with a due date of 2022-03-17. Organizations running Cisco network infrastructure should treat this as an urgent remediation item and confirm whether any IOS, IOS XR [truncated]
CVE-2018-0174 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. That KEV listing is an important defensive signal: even without a CVSS score in the supplied data, the vulnerability is considered actively exploited or at least known to be exploited, so Cisco device owners should treat remediation as urgent.
CVE-2018-0173 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The key defensive takeaway is straightforward: treat this as a high-priority remediation item and apply Cisco-recommended updates as soon as possible.
CVE-2018-0172 is a Cisco IOS and IOS XE Software improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat affected Cisco network devices as a priority for inventory, patching, and validation against Cisco guidance.
CVE-2018-0167 is a Cisco IOS, XR, and XE Software buffer overflow vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because KEV inclusion indicates observed exploitation, organizations running Cisco IOS, XR, or XE should treat remediation as urgent and follow Cisco’s update guidance.
CVE-2018-0161 is a Cisco IOS Software vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied record identifies it as a Cisco IOS Software resource management errors issue and directs defenders to apply updates per vendor instructions. Because it appears in the KEV catalog, it should be treated as a confirmed exploitation risk rather than a theoretical issue.
CVE-2018-0159 is a Cisco IOS Software and Cisco IOS XE Software denial-of-service vulnerability affecting Internet Key Exchange version 1 (IKEv1). CISA includes it in the Known Exploited Vulnerabilities catalog, which means it should be treated as a remediation priority for environments running the affected Cisco platforms. The supplied CISA record directs teams to apply updates per vendor instructions.
CVE-2018-0158 is a Cisco IOS Software and Cisco IOS XE Software Internet Key Exchange memory leak vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known exploitation and a required remediation window by 2022-03-17. The official guidance in the supplied corpus is to apply updates per vendor instructions.
CVE-2018-0156 is a Cisco IOS Software and Cisco IOS XE Software Smart Install denial-of-service vulnerability. CISA has included it in the Known Exploited Vulnerabilities (KEV) catalog, which means defenders should treat it as actively important to address. The KEV entry directs organizations to apply updates per vendor instructions.
CVE-2018-0155 is a Cisco Catalyst Bidirectional Forwarding Detection (BFD) denial-of-service vulnerability affecting Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches. In the supplied records, CISA lists the issue in its Known Exploited Vulnerabilities catalog, so it should be treated as a high-priority remediation item. The source corpus does not provide CVSS scoring or exploi [truncated]
CVE-2018-0154 is a Cisco IOS Software denial-of-service issue affecting the Integrated Services Module for VPN. CISA lists it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as actively exploited and prioritize remediation on exposed Cisco IOS systems.
CVE-2018-0151 is a Cisco IOS and IOS XE Software vulnerability affecting Quality of Service functionality and described as a remote code execution issue. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, indicating it has been observed as exploited in the wild. The defensive takeaway is straightforward: prioritize vendor-recommended updates on affected Cisco network devices.
CVE-2017-6744 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Cisco IOS software SNMP remote code execution issue. Because it appears in KEV, defenders should treat it as actively important and prioritize remediation using vendor guidance.