Vulnerabilidades en Cisco

3366 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2019-1732MEDIUMCisco NX-OS Software Remote Package Manager Command Injection VulnerabilityEPSS 0.4%CVE-2025-20285MEDIUMCisco Identity Services Engine IP Filter Access Restriction for Admin Access Configuration Bypass VulnerabilityEPSS 0.4%CVE-2026-20285MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-20364MEDIUMA vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remoEPSS 0.4%CVE-2024-20420MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Privilege Escalation VulnerabilityEPSS 0.4%CVE-2025-20264MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-20251MEDIUMA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker EPSS 0.4%CVE-2024-20270MEDIUMA vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended ServiceEPSS 0.4%CVE-2020-3215MEDIUMCisco IOS XE Software Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-20101HIGHA vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unEPSS 0.4%CVE-2026-20084HIGHA vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packetsEPSS 0.4%CVE-2020-3214MEDIUMCisco IOS XE Software Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-20086HIGHA vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless ControllerEPSS 0.4%CVE-2026-20012HIGHA vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall AEPSS 0.4%CVE-2025-20335MEDIUMCisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Firmware Information Arbitrary File Write VulnerabilityEPSS 0.4%CVE-2024-20531MEDIUMCisco Identity Services Engine XML External Entity Injection VulnerabilityEPSS 0.4%CVE-2024-20476MEDIUMCisco Identity Services Engine Authorization Bypass VulnerabilityEPSS 0.4%CVE-2024-20305MEDIUMA vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cEPSS 0.4%CVE-2020-3234HIGHCisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials VulnerabilityEPSS 0.4%CVE-2019-1682HIGHCisco Application Policy Infrastructure Controller Privilege Escalation VulnerabilityEPSS 0.4%