Vulnerabilidades en Cisco

3366 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2024-20457MEDIUMCisco Unified Communications Manager IM & Presence Service Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-20318CRITICALCisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Validation VulnerabilitiesEPSS 0.4%CVE-2021-1284HIGHCisco SD-WAN vManage Software Authentication Bypass VulnerabilityEPSS 0.4%CVE-2022-20955MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2022-20954MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software VulnerabilitiesEPSS 0.4%CVE-2025-20183MEDIUMCisco Secure Web Appliance Range Request Bypass VulnerabilityEPSS 0.4%CVE-2023-20230MEDIUMA vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow anEPSS 0.4%CVE-2020-3173HIGHCisco UCS Manager Software Local Management CLI Command Injection VulnerabilityEPSS 0.4%CVE-2026-20199MEDIUMA vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to exeEPSS 0.4%CVE-2019-1836MEDIUMCisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Symbolic Link Path Traversal VulnerabilityEPSS 0.4%CVE-2023-20179MEDIUMA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenEPSS 0.4%CVE-2024-20390MEDIUMCisco IOS XR Software Dedicated XML Agent TCP Denial of Service VulnerabilityEPSS 0.4%CVE-2026-20314MEDIUMCisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server-Side Request Forgery VulnerabilityEPSS 0.4%CVE-2022-20961HIGHA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attackeEPSS 0.4%CVE-2019-12717MEDIUMCisco NX-OS Software Virtualization Manager Command Injection VulnerabilityEPSS 0.4%CVE-2020-3216MEDIUMCisco IOS XE SD-WAN Software Authentication Bypass VulnerabilityEPSS 0.4%CVE-2026-20283MEDIUMCisco Identity Services Engine IPSec Open API Command Injection VulnerabilityEPSS 0.4%CVE-2021-1308HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-1251HIGHCisco Small Business RV Series Routers Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2020-3511HIGHCisco IOS and IOS XE Software ISDN Q.931 Denial of Service VulnerabilityEPSS 0.4%