Vulnerabilidades en Cisco

3365 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2026-20342HIGHCisco Secure Firewall Management Center Software Low Privileged Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2019-1632MEDIUMCisco Integrated Management Controller Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2023-20232MEDIUMA vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote aEPSS 0.5%CVE-2021-1137HIGHCisco SD-WAN vManage Software VulnerabilitiesEPSS 0.5%CVE-2026-20295HIGHCisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Memory Exhaustion Denial of Service VulnerabilityEPSS 0.5%CVE-2024-20493MEDIUMA vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) SoEPSS 0.5%CVE-2026-20250HIGHCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series DTLS Denial of Service VulnerabilityEPSS 0.5%CVE-2023-20271MEDIUMA vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) coEPSS 0.5%CVE-2026-20030CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.5%CVE-2024-20278MEDIUMA vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root EPSS 0.5%CVE-2019-1805MEDIUMCisco Wireless LAN Controller Secure Shell Unauthorized Access VulnerabilityEPSS 0.5%CVE-2025-20271HIGHCisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service VulnerabilityEPSS 0.5%CVE-2022-20967MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conEPSS 0.5%CVE-2019-1605HIGHCisco NX-OS Software NX-API Arbitrary Code Execution VulnerabilityEPSS 0.5%CVE-2025-20209HIGHCisco IOS XR Software Internet Key Exchange Version 2 Denial of Service VulnerabilityEPSS 0.5%CVE-2023-20070MEDIUMA vulnerability in the TLS 1.3 implementation of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote atEPSS 0.5%CVE-2025-20142HIGHCisco IOS XR Software for ASR 9000 Series Routers L2VPN Denial of Service VulnerabilityEPSS 0.5%CVE-2025-20244HIGHCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service VulnerabilityEPSS 0.5%CVE-2020-3135MEDIUMCisco Unified Communications Manager Cross-Site Request Forgery VulnerabilityEPSS 0.5%CVE-2022-20792HIGHA vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 aEPSS 0.5%