PatchSiren

Cisco CVE debriefs · Page 9

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6743

CVE-2017-6743 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is a known exploited issue affecting network infrastructure software, it should be treated as a high-priority remediation item. Cisco and CISA guidance in the supplied sources points to applying vendor updates per instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6740

CVE-2017-6740 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a priority for remediation on affected Cisco devices.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6739

CVE-2017-6739 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV status makes this a defensive priority for any environment running affected Cisco network devices, especially where SNMP is enabled or reachable from management or adjacent networks. The supplied CISA entry directs defenders to apply update [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6738

CVE-2017-6738 is a Cisco IOS and IOS XE Software vulnerability described by Cisco and CISA as an SNMP remote code execution issue. CISA added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a high-priority remediation item and apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6737

CVE-2017-6737 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not just that the issue exists, but that it was deemed actively exploited and should be treated as a high-priority patching item for any exposed Cisco network device running affected software.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6736

CVE-2017-6736 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a remediation due date of 2022-03-24, which means defenders should treat it as actively exploited and prioritize vendor-directed patching.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6663

CVE-2017-6663 is a Cisco IOS and IOS XE Software denial-of-service vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied official sources direct defenders to apply vendor updates, making this a priority for organizations running Cisco network infrastructure.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-6627

CVE-2017-6627 is a Cisco IOS and IOS XE Software denial-of-service issue affecting UDP packet processing. CISA has included it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a prioritized remediation item and follow vendor update guidance.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12319

Cisco IOS XE Software CVE-2017-12319 is a denial-of-service vulnerability tied to Ethernet Virtual Private Network (EVPN) Border Gateway Protocol (BGP) handling. CISA lists it in the Known Exploited Vulnerabilities catalog, so it should be treated as a known-exploited exposure and remediated according to Cisco’s instructions as soon as possible.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12240

CVE-2017-12240 is a Cisco IOS and IOS XE Software vulnerability described by CISA as a DHCP remote code execution issue. Because it appears in CISA’s Known Exploited Vulnerabilities catalog, it should be treated as a high-priority remediation item for organizations running affected Cisco network software.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12238

CVE-2017-12238 is a Cisco Catalyst 6800 Series Switches vulnerability described by CISA as a VPLS denial-of-service issue. Because it is listed in CISA’s Known Exploited Vulnerabilities catalog, defenders should treat it as a priority remediation item for any affected Catalyst 6800 Series deployment. The official guidance in the supplied corpus is to apply updates per vendor instructions.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12237

CVE-2017-12237 is a Cisco IOS and IOS XE Software Internet Key Exchange (IKE) denial-of-service vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as actively relevant for remediation priority. The supplied corpus does not include the underlying Cisco advisory text, so this debrief stays limited to the official record titles and KEV metadata.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12235

CVE-2017-12235 affects Cisco IOS software for Cisco Industrial Ethernet Switches and is described as a PROFINET denial-of-service vulnerability. It is included in CISA's Known Exploited Vulnerabilities catalog, which makes this a higher-priority remediation item for defenders. The supplied records do not include a CVSS score or deeper technical breakdown, so response should focus on inventory, exposure re [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12234

CVE-2017-12234 is a Cisco IOS software vulnerability tied to Common Industrial Protocol request handling that can lead to a denial-of-service condition. CISA has added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a high-priority remediation item rather than a routine maintenance fix.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12233

CVE-2017-12233 affects Cisco IOS software and is described as a Common Industrial Protocol (CIP) request denial-of-service vulnerability. Because CISA lists it in the Known Exploited Vulnerabilities catalog, defenders should treat it as a high-priority remediation item and verify whether any Cisco IOS devices in industrial or operational networks are exposed.

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12232

CVE-2017-12232 is a Cisco IOS Software denial-of-service vulnerability affecting Cisco Integrated Services Routers. CISA added it to the Known Exploited Vulnerabilities catalog, which indicates observed exploitation and makes remediation a priority. The supplied source corpus does not provide deeper technical detail, so the safest defensive posture is to inventory affected Cisco ISR devices and apply Cisc [truncated]

Known exploited Cisco CVE published 2022-03-03

CVE-2017-12231

CVE-2017-12231 is a Cisco IOS Software vulnerability affecting Network Address Translation (NAT) functionality and classified as a denial-of-service issue. CISA included it in the Known Exploited Vulnerabilities catalog on 2022-03-03, with a remediation due date of 2022-03-24. The official source corpus provided here does not include deeper technical details, so the safest defensive takeaway is that Cisco [truncated]

Known exploited Cisco CVE published 2021-11-03

CVE-2021-1498

CVE-2021-1498 is a Cisco HyperFlex HX Data Platform command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is a known exploited issue, organizations running Cisco HyperFlex HX should treat remediation as urgent and follow Cisco’s update guidance.

Known exploited Cisco CVE published 2021-11-03

CVE-2021-1497

CVE-2021-1497 is a Cisco HyperFlex HX Installer Virtual Machine command injection vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because it appears in KEV, organizations using Cisco HyperFlex HX should treat remediation as urgent and follow Cisco’s update guidance without delay.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3580

CVE-2020-3580 is a cross-site scripting vulnerability affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD). CISA lists it in the Known Exploited Vulnerabilities catalog and marks it as associated with known ransomware campaign use, so defenders should treat it as a high-priority remediation item and follow Cisco's update guidance without delay.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3569

CVE-2020-3569 is a Cisco IOS XR Software DVMRP memory exhaustion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is identified as a known exploited issue, affected Cisco IOS XR environments should be prioritized for remediation according to vendor guidance and internal change procedures.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3566

CVE-2020-3566 is a Cisco IOS XR Software DVMRP memory exhaustion vulnerability that CISA has listed in the Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is simple: this issue has been publicly identified as known exploited, so IOS XR environments should be reviewed and updated using Cisco’s guidance as soon as possible.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3452

CVE-2020-3452 affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) and is described as a read-only path traversal vulnerability. CISA has included it in the Known Exploited Vulnerabilities catalog, so affected deployments should be treated as urgent patching and validation candidates.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3161

CVE-2020-3161 affects Cisco IP Phones web server functionality and is described as a remote code execution and denial-of-service vulnerability. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03, which means defenders should treat it as actively exploited risk and prioritize vendor-guided patching and mitigation.

Known exploited Cisco CVE published 2021-11-03

CVE-2020-3118

CVE-2020-3118 is a Cisco IOS XR software vulnerability described as a Discovery Protocol format string issue. It is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, which means defenders should treat it as an active risk and prioritize vendor-recommended updates.

Known exploited Cisco CVE published 2021-11-03

CVE-2019-1653

CVE-2019-1653 is a Cisco Small Business RV320 and RV325 Routers information disclosure vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog, which means it is tracked as known to be exploited in the wild. The defensive takeaway is straightforward: prioritize vendor updates and verify that any affected Cisco Small Business RV320/RV325 devices are remediated according to Cisco guidance.

Known exploited Cisco CVE published 2021-11-03

CVE-2018-0296

CVE-2018-0296 is a denial-of-service vulnerability affecting Cisco Adaptive Security Appliance (ASA). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog, which means it is considered known to be exploited in the wild. The supplied source set does not include exploit details or affected version ranges, so the safest response is to prioritize Cisco’s updates and remediation guidance.

Known exploited Cisco CVE published 2021-11-03

CVE-2018-0171

CVE-2018-0171 is a Cisco IOS and IOS XE Smart Install remote code execution issue that CISA has placed in its Known Exploited Vulnerabilities catalog. That KEV inclusion means defenders should treat it as actively exploited risk and prioritize remediation on affected network devices. The supplied corpus directs operators to apply Cisco updates per vendor instructions.

HIGH Cisco CVE published 2017-03-01

CVE-2017-3826

CVE-2017-3826 is a denial-of-service vulnerability in Cisco NetFlow Generation Appliance (NGA) software before 1.1(1a). According to Cisco and NVD, malformed SCTP packets seen on NGA data ports can trigger incomplete packet validation, causing the appliance to hang or unexpectedly reload. The issue is remotely reachable, requires no authentication, and impacts availability only.

MEDIUM Cisco CVE published 2017-02-22

CVE-2017-3847

CVE-2017-3847 is a medium-severity cross-site scripting (XSS) issue in the web framework of Cisco Firepower Management Center. According to the CVE and NVD record, an authenticated remote attacker could trigger XSS against a user of the web interface. The vulnerability is associated with Cisco Firepower Management Center 6.2.1 and carries a CVSS v3.0 score of 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).