<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cisco IOS XE (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/cisco-ios-xe.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cisco-ios-xe-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cisco IOS XE (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20125 – A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20125</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20125</strong></p>
  <p>A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP re…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-228</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20086 – A vulnerability in the processing of Control and Provisioning of Wireless Access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20086</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20086</strong></p>
  <p>A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of a malformed CAPWAP packet. An attacker could expl…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20084 – A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20084</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20084</strong></p>
  <p>A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.   This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20012 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20012</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20012</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device.  This vulner…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20004 – A vulnerability in the TLS library of Cisco IOS XE Software could allow an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20004</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20004</strong></p>
  <p>A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.  This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be do…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-771</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20363 – A vulnerability in the web services of Cisco Secure Firewall Adaptive Security A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20363</guid>
    <pubDate>Thu, 25 Sep 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20363</strong></p>
  <p>A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privil…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20352 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20352</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20352</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:   An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or ear…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20315 – A vulnerability in the Network-Based Application Recognition (NBAR) feature of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20315</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20315</strong></p>
  <p>A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition.  This vulnerability is due to improper handling of malformed Control and Provisioning of Wireless Access Points (CAPWAP) packets. An attacker could exploit this vul…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20312 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20312</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20312</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affec…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20311 – A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20311</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20311</strong></p>
  <p>A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic.  This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20160 – A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20160</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20160</strong></p>
  <p>A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication.   This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-middle attacker could exploit this vulnerabi…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20334 – A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20334</guid>
    <pubDate>Wed, 24 Sep 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20334</strong></p>
  <p>A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system.  This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by authenticating to an affected system and performing an API call…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20202 – A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20202</guid>
    <pubDate>Wed, 07 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20202</strong></p>
  <p>A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless controller. An attacker could exploit this vulner…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20192 – A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20192</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20192</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The attacker must have valid IKEv1 VPN credentials to exploit this vulnerability.  This vulnerability is due to improper validation of IKEv1 phase 2 parameters before the IPsec security association crea…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-232</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20191 – A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20191</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20191</strong></p>
  <p>A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to the incorrect handling of DHCPv6 packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20189 – A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20189</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20189</strong></p>
  <p>A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition.  This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-762</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20188 – A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20188</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20188</strong></p>
  <p>A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.  This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected sys…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20186 – A vulnerability in the web-based management interface of the Wireless LAN Contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20186</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20186</strong></p>
  <p>A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affected device.  This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20182 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20182</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20182</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input val…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20162 – A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20162</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20162</strong></p>
  <p>A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition.  This vulnerability is due to improper handling of DHCP request packets. An attacker could exploit this vulnerability by sending DHCP request packets to an affected device.…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20154 – A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20154</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20154</strong></p>
  <p>A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server&nbsp;process to reload unexpectedly if debugs are e…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20140 – A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20140</guid>
    <pubDate>Wed, 07 May 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20140</strong></p>
  <p>A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition.  This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wi…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20176 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20176</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20176</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20175 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20175</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20175</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20174 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20174</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20174</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20173 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20173</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20173</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20172 – A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20172</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20172</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. For Cisco…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20171 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20171</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20171</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20170 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20170</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20170</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20169 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20169</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20169</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20480 – A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20480</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20480</strong></p>
  <p>A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover.    This vulnerability is due to improper handling of IPv4 DHCP packets. An att…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-783</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20467 – A vulnerability in the implementation of the IPv4 fragmentation reassembly code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20467</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20467</strong></p>
  <p>A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerability by sending specific sizes of fragmented…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20464 – A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20464</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20464</strong></p>
  <p>A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a crafted PIMv2 packet to a PIM-enabled interf…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20455 – A vulnerability in the process that classifies traffic that is going to the Unif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20455</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20455</strong></p>
  <p>A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability exists because UTD improperly handles certain packets as those packets egress an SD-WAN IPsec tunnel.…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-371</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20437 – A vulnerability in the web-based management interface of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20437</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20437</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device.  This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerab…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20436 – A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Tel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20436</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20436</strong></p>
  <p>A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20433 – A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20433</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20433</strong></p>
  <p>A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An attacker could exploit this vulnerability…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20313 – A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20313</guid>
    <pubDate>Wed, 24 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20313</strong></p>
  <p>A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploit this vulnerability by sending a malformed OS…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20308 – A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20308</guid>
    <pubDate>Wed, 27 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20308</strong></p>
  <p>A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.  This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an af…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20314 – A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20314</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20314</strong></p>
  <p>A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit t…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-783</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20312 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protoc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20312</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20312</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by se…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20311 – A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20311</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20311</strong></p>
  <p>A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.  This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to an affected device. A successful exploit c…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20303 – A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Soft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20303</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20303</strong></p>
  <p>A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.  This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to the wireless network and sending a continuou…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20259 – A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20259</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20259</strong></p>
  <p>A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker could exploit this vulnerability by sending a…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20273 – A vulnerability in the web UI feature of Cisco IOS XE Software could allow an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20273</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20273</strong></p>
  <p>A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating syst…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-20198 – Cisco is providing an update for the ongoing investigation into observed exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20198</guid>
    <pubDate>Mon, 16 Oct 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-20198</strong></p>
  <p>Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 comman…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-420</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20231 – A vulnerability in the web UI of Cisco IOS XE Software could allow an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20231</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20231</strong></p>
  <p>A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.  This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary Cisco IOS XE Software CL…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20227 – A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20227</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20227</strong></p>
  <p>A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful explo…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-388</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20226 – A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20226</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20226</strong></p>
  <p>A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker cou…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-456</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20187 – A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20187</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20187</strong></p>
  <p>A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.   This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned o…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-823</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20186 – A vulnerability in the Authentication, Authorization, and Accounting (AAA) featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20186</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20186</strong></p>
  <p>A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP).  This vulnerability is due to incorrect processing of SCP commands in AAA command auth…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20033 – A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 38...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20033</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20033</strong></p>
  <p>A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper resource management when processing traffic that is received on the management interface. An attacker could e…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20072 – A vulnerability in the fragmentation handling code of tunnel protocol packets in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20072</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20072</strong></p>
  <p>A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel protocol packets. One example of a tunnel protocol is Generic Routing Encapsulati…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20067 – A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20067</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20067</strong></p>
  <p>A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit this vulnerability by sending crafted traffic through a…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20065 – A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20065</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20065</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20065</strong></p>
  <p>A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.   This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successf…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20065">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20035 – A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20035</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20035</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected device using either local terminal access or…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-146</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20027 – A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassemb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20027</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20027</strong></p>
  <p>A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel interface or on a physical interface that is…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20920 – A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20920</guid>
    <pubDate>Mon, 10 Oct 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20920</strong></p>
  <p>A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affected device and sending specific SSH requests. A…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20915 – A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Bas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20915</guid>
    <pubDate>Mon, 10 Oct 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20915</strong></p>
  <p>A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling of an IPv6 packet that is forwarded from an MPLS and ZBFW-enabled interface in a 6VPE deployment. An att…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-115</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20870 – A vulnerability in the egress MPLS packet processing function of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20870</guid>
    <pubDate>Mon, 10 Oct 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20870</strong></p>
  <p>A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation of IPv4 traffic. An attacker…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20837 – A vulnerability in the DNS application layer gateway (ALG) functionality that is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20837</guid>
    <pubDate>Mon, 10 Oct 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20837</strong></p>
  <p>A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a logic error that occurs when an affected device inspects certain TCP DNS packets. An attacker could exploit this vulnerability by sen…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20919 – A vulnerability in the processing of malformed Common Industrial Protocol (CIP) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20919</guid>
    <pubDate>Fri, 30 Sep 2022 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20919</strong></p>
  <p>A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input validation during processing of CIP packets. An att…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20856 – A vulnerability in the processing of Control and Provisioning of Wireless Access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20856</guid>
    <pubDate>Fri, 30 Sep 2022 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20856</strong></p>
  <p>A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error and improper management of resources related to the…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-664</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20855 – A vulnerability in the self-healing functionality of Cisco IOS XE Software for E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20855</guid>
    <pubDate>Fri, 30 Sep 2022 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20855</strong></p>
  <p>A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an authenticated, local attacker to escape the restricted controller shell and execute arbitrary commands on the underlying operating system of the access point. This vulnerability is due to improper checks throughout the restart of certain system proc…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20848 – A vulnerability in the UDP processing functionality of Cisco IOS XE Software for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20848</guid>
    <pubDate>Fri, 30 Sep 2022 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20848</strong></p>
  <p>A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of UDP datagrams. An attacker could exploit this vulnerability by sending malicious UDP datagrams to an…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20847 – A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20847</guid>
    <pubDate>Fri, 30 Sep 2022 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20847</strong></p>
  <p>A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DHCP messages. An attacker could exploit this vulnerability by sending malicious DHCP messages to an affected device. A su…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20697 – A vulnerability in the web services interface of Cisco IOS Software and Cisco IO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20697</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20697</strong></p>
  <p>A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP requests to an affected device. A successful exploi…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-691</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20692 – A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20692</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20692</strong></p>
  <p>A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource management. An attacker could exploit this vulnerability by initiating a large number of NETCONF over SSH connections. A successful exploit could…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20684 – A vulnerability in Simple Network Management Protocol (SNMP) trap generation for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20684</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20684</strong></p>
  <p>A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition on the device. This vulnerability is due to a lack of input validation of th…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20683 – A vulnerability in the Application Visibility and Control (AVC-FNF) feature of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20683</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20683</strong></p>
  <p>A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient packet verification for traffic inspected by the AVC feature. An attacker could exploit…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-124</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20682 – A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20682</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20682</strong></p>
  <p>A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to inadequate input validation of incoming CAPWAP packets encapsulating multicas…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-690</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20681 – A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Fami...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20681</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20681</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device. This vulnerability is due to insufficient validation of user privileges after the user executes certain CLI commands. An attacker could exploit this vuln…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-20678 – A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20678</guid>
    <pubDate>Fri, 15 Apr 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-20678</strong></p>
  <p>A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an inter…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-413</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1529 – A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1529</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1529</guid>
    <pubDate>Thu, 21 Oct 2021 03:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1529</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the system CLI. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1529">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34770 – A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34770</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34770</strong></p>
  <p>A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34769 – Multiple vulnerabilities in the Control and Provisioning of Wireless Access Poin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34769</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34769</strong></p>
  <p>Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34768 – Multiple vulnerabilities in the Control and Provisioning of Wireless Access Poin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34768</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34768</strong></p>
  <p>Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34767 – A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34767</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34767</strong></p>
  <p>A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a Layer 2 (L2) loop in a configured VLAN, resulting in a denial of service (DoS) condition for that VLAN. The vulnerability is due to a logic error when processing specific link-local IPv6 traffic. An…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-34727 – A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34727</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-34727</strong></p>
  <p>A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. A successful exploit could allow the attac…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34714 – A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34714</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34714</strong></p>
  <p>A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An attacker could exploit this vulnerability by sen…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-34699 – A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34699</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-34699</strong></p>
  <p>A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run through the web UI. A successful exploit could…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-435</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1624 – A vulnerability in the Rate Limiting Network Address Translation (NAT) feature o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1624</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1624</strong></p>
  <p>A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An at…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1622 – A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1622</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1622</strong></p>
  <p>A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under certain conditions. An attacker could exploit th…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-833</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1621 – A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1621</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1621</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1621</strong></p>
  <p>A vulnerability in the Layer 2 punt code of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a queue wedge on an interface that receives specific Layer 2 frames, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of certain Layer 2 frames. An attacker could exploit this vulnerability by sending specific Layer 2 frames o…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1621">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1620 – A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1620</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1620</strong></p>
  <p>A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certain failure conditions. An attacker could expl…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-563</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-1619 – A vulnerability in the authentication, authorization, and accounting (AAA) funct...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1619</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-1619</strong></p>
  <p>A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denial of service (DoS) on an affected device This v…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1611 – A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1611</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1611</strong></p>
  <p>A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9800 Family Wireless Controller, Embedded Wireless Controller, and Embedded Wireless on Catalyst 9000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to impro…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1565 – Multiple vulnerabilities in the Control and Provisioning of Wireless Access Poin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1565</guid>
    <pubDate>Thu, 23 Sep 2021 03:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1565</strong></p>
  <p>Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient validation of CAPWAP packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1373 – A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1373</guid>
    <pubDate>Wed, 24 Mar 2021 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1373</strong></p>
  <p>A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient validation of CAPWAP packets. An attac…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1352 – A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1352</guid>
    <pubDate>Wed, 24 Mar 2021 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1352</strong></p>
  <p>A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of DECnet traffic that is received by an affected device. An attacker could exploit this vulnerability by sending DECnet tra…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-823</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1451 – A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1451</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1451</strong></p>
  <p>A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device. The vulnerability is due to incorrect boundary checks of certain values in Easy VSS pro…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1446 – A vulnerability in the DNS application layer gateway (ALG) functionality used by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1446</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1446</strong></p>
  <p>A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a logic error that occurs when an affected device inspects certain DNS packets. An attacker could exploit this vulnerability by sending crafted…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1442 – A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1442</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1442</strong></p>
  <p>A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device. The vulnerability is due to insufficient protection of sensitive information. An attacker with low privileges could exploit this vulnerability by issuing the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1435 – A vulnerability in the web UI of Cisco IOS XE Software could allow an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1435</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1435</strong></p>
  <p>A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to the web UI of an affected device with arbitrary commands injected into a portion of the reque…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1433 – A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1433</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1433</strong></p>
  <p>A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. The attacker must have a man-in-the-middle positio…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1432 – A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1432</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1432</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exp…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1431 – A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1431</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1431</strong></p>
  <p>A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1403 – A vulnerability in the web UI feature of Cisco IOS XE Software could allow an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1403</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1403</strong></p>
  <p>A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient HTTP protections in the web UI on an affected device. An attacker could exploit this vulnerability by persuading an au…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-1392 – A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1392</guid>
    <pubDate>Wed, 24 Mar 2021 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-1392</strong></p>
  <p>A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip security CLI command. An attacker could exploit thi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3526 – A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3526</guid>
    <pubDate>Thu, 24 Sep 2020 18:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3526</strong></p>
  <p>A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a malformed COPS message to the device. A successful exploit could allow the attacker…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3526">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
