These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-6743 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is a known exploited issue affecting network infrastructure software, it should be treated as a high-priority remediation item. Cisco and CISA guidance in the supplied sources points to applying vendor updates per instructions.
CVE-2017-6740 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, which makes it a priority for remediation on affected Cisco devices.
CVE-2017-6739 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV status makes this a defensive priority for any environment running affected Cisco network devices, especially where SNMP is enabled or reachable from management or adjacent networks. The supplied CISA entry directs defenders to apply update [truncated]
CVE-2017-6738 is a Cisco IOS and IOS XE Software vulnerability described by Cisco and CISA as an SNMP remote code execution issue. CISA added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a high-priority remediation item and apply updates per vendor instructions.
CVE-2017-6737 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not just that the issue exists, but that it was deemed actively exploited and should be treated as a high-priority patching item for any exposed Cisco network device running affected software.
CVE-2017-6736 is a Cisco IOS and IOS XE Software SNMP remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a remediation due date of 2022-03-24, which means defenders should treat it as actively exploited and prioritize vendor-directed patching.
CVE-2017-6663 is a Cisco IOS and IOS XE Software denial-of-service vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied official sources direct defenders to apply vendor updates, making this a priority for organizations running Cisco network infrastructure.
CVE-2017-6627 is a Cisco IOS and IOS XE Software denial-of-service issue affecting UDP packet processing. CISA has included it in the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a prioritized remediation item and follow vendor update guidance.
Cisco IOS XE Software CVE-2017-12319 is a denial-of-service vulnerability tied to Ethernet Virtual Private Network (EVPN) Border Gateway Protocol (BGP) handling. CISA lists it in the Known Exploited Vulnerabilities catalog, so it should be treated as a known-exploited exposure and remediated according to Cisco’s instructions as soon as possible.
CVE-2017-12240 is a Cisco IOS and IOS XE Software vulnerability described by CISA as a DHCP remote code execution issue. Because it appears in CISA’s Known Exploited Vulnerabilities catalog, it should be treated as a high-priority remediation item for organizations running affected Cisco network software.
CVE-2017-12238 is a Cisco Catalyst 6800 Series Switches vulnerability described by CISA as a VPLS denial-of-service issue. Because it is listed in CISA’s Known Exploited Vulnerabilities catalog, defenders should treat it as a priority remediation item for any affected Catalyst 6800 Series deployment. The official guidance in the supplied corpus is to apply updates per vendor instructions.
CVE-2017-12237 is a Cisco IOS and IOS XE Software Internet Key Exchange (IKE) denial-of-service vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as actively relevant for remediation priority. The supplied corpus does not include the underlying Cisco advisory text, so this debrief stays limited to the official record titles and KEV metadata.
CVE-2017-12235 affects Cisco IOS software for Cisco Industrial Ethernet Switches and is described as a PROFINET denial-of-service vulnerability. It is included in CISA's Known Exploited Vulnerabilities catalog, which makes this a higher-priority remediation item for defenders. The supplied records do not include a CVSS score or deeper technical breakdown, so response should focus on inventory, exposure re [truncated]
CVE-2017-12234 is a Cisco IOS software vulnerability tied to Common Industrial Protocol request handling that can lead to a denial-of-service condition. CISA has added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as a high-priority remediation item rather than a routine maintenance fix.
CVE-2017-12233 affects Cisco IOS software and is described as a Common Industrial Protocol (CIP) request denial-of-service vulnerability. Because CISA lists it in the Known Exploited Vulnerabilities catalog, defenders should treat it as a high-priority remediation item and verify whether any Cisco IOS devices in industrial or operational networks are exposed.
CVE-2017-12232 is a Cisco IOS Software denial-of-service vulnerability affecting Cisco Integrated Services Routers. CISA added it to the Known Exploited Vulnerabilities catalog, which indicates observed exploitation and makes remediation a priority. The supplied source corpus does not provide deeper technical detail, so the safest defensive posture is to inventory affected Cisco ISR devices and apply Cisc [truncated]
CVE-2017-12231 is a Cisco IOS Software vulnerability affecting Network Address Translation (NAT) functionality and classified as a denial-of-service issue. CISA included it in the Known Exploited Vulnerabilities catalog on 2022-03-03, with a remediation due date of 2022-03-24. The official source corpus provided here does not include deeper technical details, so the safest defensive takeaway is that Cisco [truncated]
CVE-2021-1498 is a Cisco HyperFlex HX Data Platform command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is a known exploited issue, organizations running Cisco HyperFlex HX should treat remediation as urgent and follow Cisco’s update guidance.
CVE-2021-1497 is a Cisco HyperFlex HX Installer Virtual Machine command injection vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because it appears in KEV, organizations using Cisco HyperFlex HX should treat remediation as urgent and follow Cisco’s update guidance without delay.
CVE-2020-3580 is a cross-site scripting vulnerability affecting Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD). CISA lists it in the Known Exploited Vulnerabilities catalog and marks it as associated with known ransomware campaign use, so defenders should treat it as a high-priority remediation item and follow Cisco's update guidance without delay.
CVE-2020-3569 is a Cisco IOS XR Software DVMRP memory exhaustion vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is identified as a known exploited issue, affected Cisco IOS XR environments should be prioritized for remediation according to vendor guidance and internal change procedures.
CVE-2020-3566 is a Cisco IOS XR Software DVMRP memory exhaustion vulnerability that CISA has listed in the Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is simple: this issue has been publicly identified as known exploited, so IOS XR environments should be reviewed and updated using Cisco’s guidance as soon as possible.
CVE-2020-3452 affects Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) and is described as a read-only path traversal vulnerability. CISA has included it in the Known Exploited Vulnerabilities catalog, so affected deployments should be treated as urgent patching and validation candidates.
CVE-2020-3161 affects Cisco IP Phones web server functionality and is described as a remote code execution and denial-of-service vulnerability. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-03, which means defenders should treat it as actively exploited risk and prioritize vendor-guided patching and mitigation.
CVE-2020-3118 is a Cisco IOS XR software vulnerability described as a Discovery Protocol format string issue. It is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, which means defenders should treat it as an active risk and prioritize vendor-recommended updates.
CVE-2019-1653 is a Cisco Small Business RV320 and RV325 Routers information disclosure vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog, which means it is tracked as known to be exploited in the wild. The defensive takeaway is straightforward: prioritize vendor updates and verify that any affected Cisco Small Business RV320/RV325 devices are remediated according to Cisco guidance.
CVE-2018-0296 is a denial-of-service vulnerability affecting Cisco Adaptive Security Appliance (ASA). CISA added it to the Known Exploited Vulnerabilities (KEV) catalog, which means it is considered known to be exploited in the wild. The supplied source set does not include exploit details or affected version ranges, so the safest response is to prioritize Cisco’s updates and remediation guidance.
CVE-2018-0171 is a Cisco IOS and IOS XE Smart Install remote code execution issue that CISA has placed in its Known Exploited Vulnerabilities catalog. That KEV inclusion means defenders should treat it as actively exploited risk and prioritize remediation on affected network devices. The supplied corpus directs operators to apply Cisco updates per vendor instructions.
CVE-2017-3826 is a denial-of-service vulnerability in Cisco NetFlow Generation Appliance (NGA) software before 1.1(1a). According to Cisco and NVD, malformed SCTP packets seen on NGA data ports can trigger incomplete packet validation, causing the appliance to hang or unexpectedly reload. The issue is remotely reachable, requires no authentication, and impacts availability only.
CVE-2017-3847 is a medium-severity cross-site scripting (XSS) issue in the web framework of Cisco Firepower Management Center. According to the CVE and NVD record, an authenticated remote attacker could trigger XSS against a user of the web interface. The vulnerability is associated with Cisco Firepower Management Center 6.2.1 and carries a CVSS v3.0 score of 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).