<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Cisco IOS XE</title>
  <link>https://cvedaily.com/pages/tags/cisco-ios-xe.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cisco-ios-xe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Cisco IOS XE</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-20125 – A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20125</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20125</strong></p>
  <p>A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP re…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-228</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20115 – A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20115</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20115</strong></p>
  <p>A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information.  This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20114 – A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20114</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20114</strong></p>
  <p>A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.   This vulnerability exists because parameters that are received by an API endpoint are not sufficiently validated. An attacker could exploit…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20113 – A vulnerability in the web-based Cisco IOx application hosting environment manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20113</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20113</strong></p>
  <p>A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.  This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an af…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20112 – A vulnerability in the web-based Cisco IOx application hosting environment manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20112</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20112</strong></p>
  <p>A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could expl…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20110 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20110</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20110</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability exists because incorrect privileges are associated with the start maintenance command. An attacker could exploit this vulnerability by accessing the management CLI of the affected device as a low-privileged user…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20104 – A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 92...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20104</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20104</strong></p>
  <p>A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected devic…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-124</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20086 – A vulnerability in the processing of Control and Provisioning of Wireless Access...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20086</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20086</strong></p>
  <p>A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of a malformed CAPWAP packet. An attacker could expl…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-230</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20084 – A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20084</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20084</strong></p>
  <p>A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.   This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20083 – A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20083</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20083</strong></p>
  <p>A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of a malformed SCP request. An attacker could exploit this vulnerability by issuing a crafted command through SSH. A successfu…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-235</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20012 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20012</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20012</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device.  This vulner…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20004 – A vulnerability in the TLS library of Cisco IOS XE Software could allow an unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20004</guid>
    <pubDate>Wed, 25 Mar 2026 16:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20004</strong></p>
  <p>A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.  This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be do…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-771</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20363 – A vulnerability in the web services of Cisco Secure Firewall Adaptive Security A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20363</guid>
    <pubDate>Thu, 25 Sep 2025 16:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20363</strong></p>
  <p>A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privil…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20352 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20352</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20352</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:   An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or ear…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20338 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20338</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20338</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device.  This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by logging in…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-141</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20316 – A vulnerability in the access control list (ACL) programming of Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20316</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20316</strong></p>
  <p>A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software for Cisco Catalyst 9500X and 9600X Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL on an affected device.  This vulnerability is due to the flooding of traffic from an unlearned MAC address on a switch virtual interface (SVI) that has an egress ACL applied. An attacke…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20315 – A vulnerability in the Network-Based Application Recognition (NBAR) feature of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20315</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20315</strong></p>
  <p>A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, causing a denial of service (DoS) condition.  This vulnerability is due to improper handling of malformed Control and Provisioning of Wireless Access Points (CAPWAP) packets. An attacker could exploit this vul…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20314 – A vulnerability in Cisco IOS XE Software could allow an authenticated, local att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20314</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20314</strong></p>
  <p>A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to improper validation of software packages. An attacker could exploit this vulnerability by placing a crafted file in…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-232</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20313 – Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20313</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20313</strong></p>
  <p>Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.  These vulnerabilities are due path traversal and improper image integrity validation.  A successful exploit could allow the attacker to e…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20312 – A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Ci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20312</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20312</strong></p>
  <p>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affec…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20311 – A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20311</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20311</strong></p>
  <p>A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic.  This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20293 – A vulnerability in the Day One setup process of Cisco IOS XE Software for Cataly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20293</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20293</strong></p>
  <p>A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is running on an affected device.  This vulnerability is due to incomplete cleanup upon completion of the Day One setup process. An attacker could exploit…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20240 – A vulnerability in the Web Authentication feature of Cisco IOS XE Software could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20240</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20240</strong></p>
  <p>A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device.  This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit coul…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-692</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20160 – A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20160</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20160</strong></p>
  <p>A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication.   This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-middle attacker could exploit this vulnerabi…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20149 – A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20149</guid>
    <pubDate>Wed, 24 Sep 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20149</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by using crafted commands at the CLI prompt. A succ…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20334 – A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20334</guid>
    <pubDate>Wed, 24 Sep 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20334</strong></p>
  <p>A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system.  This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by authenticating to an affected system and performing an API call…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20221 – A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20221</guid>
    <pubDate>Wed, 07 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20221</strong></p>
  <p>A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters.   This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20214 – A vulnerability in the Network Configuration Access Control Module (NACM) of Cis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20214</guid>
    <pubDate>Wed, 07 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20214</strong></p>
  <p>A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data.  This vulnerability exists because a subtle change in inner API call behavior causes results to be filtered incorrectly. An attacker could exploit this vulnerability by using eith…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20202 – A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20202</guid>
    <pubDate>Wed, 07 May 2025 18:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20202</strong></p>
  <p>A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless controller. An attacker could exploit this vulner…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20201 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20201</guid>
    <pubDate>Wed, 07 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20201</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.  This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in spec…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20200 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20200</guid>
    <pubDate>Wed, 07 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20200</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.  This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in spec…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20199 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20199</guid>
    <pubDate>Wed, 07 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20199</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.  This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in spec…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20198 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20198</guid>
    <pubDate>Wed, 07 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20198</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.  This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in spec…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20197 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20197</guid>
    <pubDate>Wed, 07 May 2025 18:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20197</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.  This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in spec…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20196 – A vulnerability in the Cisco IOx application hosting environment of Cisco IOS So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20196</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20196</strong></p>
  <p>A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition.  This vulnerability is due to the improper handling of HTTP requests. An attacker could exploit this vulnerabil…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20195 – A vulnerability in the web-based management interface of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20195</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20195</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device.   This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an alrea…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20194 – A vulnerability in the web-based management interface of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20194</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20194</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.   This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface. A successful exploit could…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20193 – A vulnerability in the web-based management interface of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20193</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20193</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r  This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface. A successful exploit could…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20192 – A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20192</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20192</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The attacker must have valid IKEv1 VPN credentials to exploit this vulnerability.  This vulnerability is due to improper validation of IKEv1 phase 2 parameters before the IPsec security association crea…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-232</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20191 – A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20191</guid>
    <pubDate>Wed, 07 May 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20191</strong></p>
  <p>A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to the incorrect handling of DHCPv6 packets. An attacker could…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20190 – A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20190</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20190</strong></p>
  <p>A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device.  This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulnerability by logging in to an affected device…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20189 – A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20189</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20189</strong></p>
  <p>A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition.  This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-762</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-20188 – A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20188</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-20188</strong></p>
  <p>A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.  This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an affected sys…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20186 – A vulnerability in the web-based management interface of the Wireless LAN Contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20186</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20186</strong></p>
  <p>A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affected device.  This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20182 – A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20182</guid>
    <pubDate>Wed, 07 May 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20182</strong></p>
  <p>A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input val…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20162 – A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20162</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20162</strong></p>
  <p>A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition.  This vulnerability is due to improper handling of DHCP request packets. An attacker could exploit this vulnerability by sending DHCP request packets to an affected device.…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20155 – A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20155</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20155</strong></p>
  <p>A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system.  This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator configures SD-Routing on the device. An attacker…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20154 – A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server featur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20154</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20154</strong></p>
  <p>A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server&nbsp;process to reload unexpectedly if debugs are e…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-20151 – A vulnerability in the implementation of the Simple Network Management Protocol ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20151</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20151</guid>
    <pubDate>Wed, 07 May 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-20151</strong></p>
  <p>A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to deny SNMP traffic from an unauthorized source or the SNMPv3 username is removed from the configuration.  This vulnerabili…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20151">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20140 – A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20140</guid>
    <pubDate>Wed, 07 May 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20140</strong></p>
  <p>A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition.  This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wi…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20176 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20176</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20176</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20175 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20175</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20175</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20174 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20174</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20174</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20173 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20173</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20173</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20172 – A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Softwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20172</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20172</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. For Cisco…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20171 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20171</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20171</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20170 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20170</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20170</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-20169 – A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-20169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-20169</guid>
    <pubDate>Wed, 05 Feb 2025 17:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-20169</strong></p>
  <p>A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.  This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-20169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20373 – A vulnerability in the implementation of the Simple Network Management Protocol ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20373</guid>
    <pubDate>Fri, 15 Nov 2024 15:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20373</strong></p>
  <p>A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it is configured to deny SNMP traffic.&nbsp;  This vulnerability exists because Cisco IOS Software and Cisco IOS XE Soft…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20510 – A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20510</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20510</strong></p>
  <p>A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication.  This vulnerability is due to a logic error when activating the pre-authentication ACL that is rece…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20508 – A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20508</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20508</strong></p>
  <p>A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation of HTTP requests when they are processed by Cisco UTD Snort I…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20480 – A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20480</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20480</strong></p>
  <p>A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover.    This vulnerability is due to improper handling of IPv4 DHCP packets. An att…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-783</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20467 – A vulnerability in the implementation of the IPv4 fragmentation reassembly code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20467</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20467</strong></p>
  <p>A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerability by sending specific sizes of fragmented…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20464 – A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20464</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20464</strong></p>
  <p>A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a crafted PIMv2 packet to a PIM-enabled interf…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20455 – A vulnerability in the process that classifies traffic that is going to the Unif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20455</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20455</strong></p>
  <p>A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability exists because UTD improperly handles certain packets as those packets egress an SD-WAN IPsec tunnel.…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-371</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20437 – A vulnerability in the web-based management interface of Cisco IOS XE Software c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20437</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20437</strong></p>
  <p>A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device.  This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerab…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20436 – A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Tel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20436</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20436</strong></p>
  <p>A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20434 – A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20434</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20434</strong></p>
  <p>A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device.  This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending crafted frames to an affected device. A successful exploit could allow the a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20433 – A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20433</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20433</strong></p>
  <p>A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An attacker could exploit this vulnerability…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20414 – A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20414</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20414</strong></p>
  <p>A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.  This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a cur…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20313 – A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20313</guid>
    <pubDate>Wed, 24 Apr 2024 21:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20313</strong></p>
  <p>A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploit this vulnerability by sending a malformed OS…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20308 – A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20308</guid>
    <pubDate>Wed, 27 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20308</strong></p>
  <p>A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.  This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an af…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20307 – A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20307</guid>
    <pubDate>Wed, 27 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20307</strong></p>
  <p>A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading.  This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an aff…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20324 – A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20324</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20324</strong></p>
  <p>A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords.  This vulnerability is due to improper privilege checks. An attacker could exploit this vulnerability by using the show and show tech wireless CLI commands to access configuration details, including passwords. A successful exp…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-274</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20316 – A vulnerability in the data model interface (DMI) services of Cisco IOS XE Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20316</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20316</strong></p>
  <p>A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL).  This vulnerability is due to improper handling of error conditions when a successfully authorized device administrator updates an IPv4 ACL using the NETCONF or REST…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20314 – A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20314</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20314</strong></p>
  <p>A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit t…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-783</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20312 – A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protoc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20312</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20312</strong></p>
  <p>A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An attacker could exploit this vulnerability by se…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20311 – A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20311</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20311</strong></p>
  <p>A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.  This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to an affected device. A successful exploit c…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20309 – A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20309</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20309</strong></p>
  <p>A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding.  This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX port. An attacker could exploit this vulnerability by reverse telnetting to…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-828</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20306 – A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20306</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20306</strong></p>
  <p>A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device.   This vulnerability is due to insufficient input validation. An attacker could e…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-233</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20303 – A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Soft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20303</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20303</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20303</strong></p>
  <p>A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.  This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to the wireless network and sending a continuou…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-459</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20303">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-20278 – A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20278</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-20278</strong></p>
  <p>A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A successful exploit could allow the attacker to eleva…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20259 – A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20259</guid>
    <pubDate>Wed, 27 Mar 2024 17:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20259</strong></p>
  <p>A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker could exploit this vulnerability by sending a…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20273 – A vulnerability in the web UI feature of Cisco IOS XE Software could allow an au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20273</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20273</strong></p>
  <p>A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating syst…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-20198 – Cisco is providing an update for the ongoing investigation into observed exploit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20198</guid>
    <pubDate>Mon, 16 Oct 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-20198</strong></p>
  <p>Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 comman…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-420</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20235 – A vulnerability in the on-device application development workflow feature for th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20235</guid>
    <pubDate>Wed, 04 Oct 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20235</strong></p>
  <p>A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user.  This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application develo…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20231 – A vulnerability in the web UI of Cisco IOS XE Software could allow an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20231</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20231</strong></p>
  <p>A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.  This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to execute arbitrary Cisco IOS XE Software CL…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20227 – A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20227</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20227</strong></p>
  <p>A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful explo…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-388</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20226 – A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20226</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20226</strong></p>
  <p>A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker cou…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-456</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20202 – A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE So...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20202</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20202</strong></p>
  <p>A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.  This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network requests to an affected device. A successful exploi…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20187 – A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20187</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20187</strong></p>
  <p>A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.   This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned o…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-823</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20186 – A vulnerability in the Authentication, Authorization, and Accounting (AAA) featu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20186</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20186</strong></p>
  <p>A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP).  This vulnerability is due to incorrect processing of SCP commands in AAA command auth…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20109 – A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20109</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20109</strong></p>
  <p>A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.  This vulnerability is due to insufficient validation of attributes in the G…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20033 – A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 38...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20033</guid>
    <pubDate>Wed, 27 Sep 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20033</strong></p>
  <p>A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to improper resource management when processing traffic that is received on the management interface. An attacker could e…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20100 – A vulnerability in the access point (AP) joining process of the Control and Prov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20100</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20100</strong></p>
  <p>A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error that occurs when certain conditions are met du…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-694</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20082 – A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20082</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20082</strong></p>
  <p>A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to errors that occur when retrieving the public release key that is used for image sig…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20081 – A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Securi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20081</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20081</strong></p>
  <p>A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of DHCPv6 messages. An attac…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20072 – A vulnerability in the fragmentation handling code of tunnel protocol packets in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20072</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20072</strong></p>
  <p>A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel protocol packets. One example of a tunnel protocol is Generic Routing Encapsulati…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20067 – A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Softw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20067</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20067</strong></p>
  <p>A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit this vulnerability by sending crafted traffic through a…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20066 – A vulnerability in the web UI of Cisco IOS XE Software could allow an authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20066</guid>
    <pubDate>Thu, 23 Mar 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20066</strong></p>
  <p>A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20066">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
