cisco security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect cisco products.
Vulnios monitors cisco CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent cisco security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2016-9223 — cisco — cloudcenter_orchestrator
A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privil
criticalCVE-2016-9223Critical Vulnerability: CVE-2016-6441 — cisco — ios_xe
A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a reload of, or remotely execute code on, the affected
criticalCVE-2016-6441Critical Vulnerability: CVE-2016-6452 — cisco — prime_home
A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full adminis
criticalCVE-2016-6452Critical Vulnerability: CVE-2016-6448 — cisco — meeting_server
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerabi
criticalCVE-2016-6448Critical Vulnerability: CVE-2016-6447 — cisco — meeting_app, meeting_server
A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following produc
criticalCVE-2016-6447Critical Vulnerability: CVE-2016-6445 — cisco — meeting_server
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an una
criticalCVE-2016-6445Critical Vulnerability: CVE-2016-6397 — cisco — ip_interoperability_and_collaboration_system
A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote atta
criticalCVE-2016-6397Critical Vulnerability: CVE-2016-1453 — cisco — nx-os
Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long param
criticalCVE-2016-1453Critical Vulnerability: CVE-2016-6394 — cisco — firesight_system_software
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug I
criticalCVE-2016-6394Critical Vulnerability: CVE-2016-6406 — cisco — email_security_appliance_firmware
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 i
criticalCVE-2016-6406Critical Vulnerability: CVE-2016-6374 — cisco — cloud_services_platform_2100
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
criticalCVE-2016-6374Critical Vulnerability: CVE-2016-1473 — cisco — small_business_220_series_smart_plus_switches
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, a
criticalCVE-2016-1473Critical Vulnerability: CVE-2016-1289 — cisco — prime_infrastructure, evolved_programmable_network_manager
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information v
criticalCVE-2016-1289Critical Vulnerability: CVE-2016-1416 — cisco — prime_collaboration_provisioning
Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administrator privileges via a crafted login attempt, aka Bug
criticalCVE-2016-1416Critical Vulnerability: CVE-2016-1395 — cisco — rv130w_wireless-n_multifunction_vpn_router, rv130w_wireless-n_multifunction_vpn_router_firmware
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote att
criticalCVE-2016-1395Critical Vulnerability: CVE-2016-1388 — cisco — network_analysis_module, prime_network_analysis_module_software
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(
criticalCVE-2016-1388Critical Vulnerability: CVE-2016-1387 — cisco — telepresence_tc_software
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles auth
criticalCVE-2016-1387Critical Vulnerability: CVE-2016-1343 — cisco — information_server
The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in con
criticalCVE-2016-1343Critical Vulnerability: CVE-2016-1363 — cisco — wireless_lan_controller_software
Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through 8.0 before 8.0.115.0(ED) allows remote attackers t
criticalCVE-2016-1363Critical Vulnerability: CVE-2016-1352 — cisco — unified_computing_system_central_software
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
criticalCVE-2016-1352Critical Vulnerability: CVE-2016-1327 — cisco — dpc2203, dpc2203_cable_modem_firmware
Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv059
criticalCVE-2016-1327Critical Vulnerability: CVE-2016-1313 — cisco — ucs_invicta_c3124sa_appliance
Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to
criticalCVE-2016-1313Critical Vulnerability: CVE-2016-1341 — cisco — nx-os
Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID C
criticalCVE-2016-1341Critical Vulnerability: CVE-2016-1287 — cisco — adaptive_security_appliance_software
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7),
criticalCVE-2016-1287Critical Vulnerability: CVE-2015-6412 — cisco — modular_encoding_platform_d9036_software, modular_encoding_platform_d9036
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug I
criticalCVE-2015-6412Critical Vulnerability: CVE-2015-6435 — cisco — firepower_extensible_operating_system, unified_computing_system
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows re
criticalCVE-2015-6435Critical Vulnerability: CVE-2015-6323 — cisco — identity_services_engine_software
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative
criticalCVE-2015-6323Critical Vulnerability: CVE-2015-6314 — cisco — wireless_lan_controller_software
Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug
criticalCVE-2015-6314Critical Vulnerability: CVE-2017-12371 — cisco — webex_meetings
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files.
criticalCVE-2017-12371Critical Vulnerability: CVE-2017-12369 — cisco — webex_meetings
A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote
criticalCVE-2017-12369Critical Vulnerability: CVE-2017-12370 — cisco — webex_meetings
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files.
criticalCVE-2017-12370Critical Vulnerability: CVE-2017-12367 — cisco — webex_meetings_server
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A re
criticalCVE-2017-12367Critical Vulnerability: CVE-2017-12368 — cisco — webex_meetings, webex_meetings_server
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files.
criticalCVE-2017-12368Critical Vulnerability: CVE-2017-12372 — cisco — webex_meetings_server, webex_meetings
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files.
criticalCVE-2017-12372Critical Vulnerability: CVE-2017-12337 — cisco — emergency_responder, finesse
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorize
criticalCVE-2017-12337Critical Vulnerability: CVE-2017-12251 — cisco — cloud_services_platform_2100
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) ope
criticalCVE-2017-12251Critical Vulnerability: CVE-2017-12229 — cisco — ios_xe
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of th
criticalCVE-2017-12229Critical Vulnerability: CVE-2017-12236 — cisco — ios_xe
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass a
criticalCVE-2017-12236Critical Vulnerability: CVE-2017-12249 — cisco — meeting_server
A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to
criticalCVE-2017-12249Critical Vulnerability: CVE-2017-6747 — cisco — identity_services_engine
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to imprope
criticalCVE-2017-6747Critical Vulnerability: CVE-2017-9479 — cisco — dpc3939_firmware, dpc3939
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network ac
criticalCVE-2017-9479Critical Vulnerability: CVE-2017-9483 — cisco — dpc3939_firmware, dpc3939
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users to obtain root access to the Application Processor
criticalCVE-2017-9483Critical Vulnerability: CVE-2017-9482 — cisco — dpc3939_firmware, dpc3939
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by
criticalCVE-2017-9482Critical Vulnerability: CVE-2017-11588 — cisco — residential_gateway_firmware, residential_gateway
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command exec
criticalCVE-2017-11588Critical Vulnerability: CVE-2017-11589 — cisco — residential_gateway_firmware, residential_gateway
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control f
criticalCVE-2017-11589Critical Vulnerability: CVE-2017-11502 — cisco — dpc3928ad_docsis_wireless_router_firmware, dpc3928ad_docsis_wireless_router
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
criticalCVE-2017-11502Critical Vulnerability: CVE-2017-6713 — cisco — elastic_services_controller
A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to
criticalCVE-2017-6713Critical Vulnerability: CVE-2017-6708 — cisco — ultra_services_framework
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files
criticalCVE-2017-6708Critical Vulnerability: CVE-2017-6714 — cisco — ultra_services_framework_staging_server
A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The v
criticalCVE-2017-6714Critical Vulnerability: CVE-2017-6709 — cisco — ultra_services_framework
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (E
criticalCVE-2017-6709Critical Vulnerability: CVE-2017-6711 — cisco — ultra_services_framework
A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulner
criticalCVE-2017-6711Critical Vulnerability: CVE-2017-6667 — cisco — context_service_development_kit
A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on
criticalCVE-2017-6667Critical Vulnerability: CVE-2017-6639 — cisco — prime_data_center_network_manager
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information
criticalCVE-2017-6639Critical Vulnerability: CVE-2017-6640 — cisco — prime_data_center_network_manager
A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account
criticalCVE-2017-6640Critical Vulnerability: CVE-2017-6622 — cisco — prime_collaboration_provisioning
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privile
criticalCVE-2017-6622Critical Vulnerability: CVE-2017-3882 — cisco — small_business_rv_router_firmware, small_business_rv_router_firmware_1.0
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or c
criticalCVE-2017-3882Critical Vulnerability: CVE-2017-3834 — cisco — aironet_access_point_firmware, aironet_1830i_access_point
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete contro
criticalCVE-2017-3834Critical Vulnerability: CVE-2017-3853 — cisco — iox
A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remo
criticalCVE-2017-3853Critical Vulnerability: CVE-2017-3831 — cisco — aironet_access_point_software, aironet_1810
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full ad
criticalCVE-2017-3831Critical Vulnerability: CVE-2017-3792 — cisco — telepresence_mcu_software, telepresence_mcu_4505
A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthenticated, remote attacker to execute arbitrary code or c
criticalCVE-2017-3792
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track cisco exposure across your environment
Vulnios automatically cross-references your asset inventory against new cisco CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan