Vulnerabilidades en Cisco

3365 resultados
Análisis Vexday

Com 3.204 CVEs catalogadas e 53 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração dos produtos Cisco está 3,7 vezes acima da média geral do catálogo, o que indica risco operacional significativamente elevado para organizações que dependem dessas tecnologias. Há ainda 199 vulnerabilidades de severidade crítica e 77 com prova de conceito pública disponível, ampliando a superfície de ataque explorável sem necessidade de capacidade ofensiva avançada. O tipo de falha mais recorrente é CWE-20 (validação de entrada inadequada), uma classe de vulnerabilidade frequentemente presente em componentes de rede e que tende a produzir impacto amplo quando explorada. A CVE mais perigosa em exploração ativa neste momento é CVE-2021-1498, com EPSS máximo de 1,0 — indicando probabilidade de exploração extremamente alta —, e deve ser tratada como prioridade imediata em qualquer processo de gestão de patches.

CVE-2021-34702MEDIUMCisco Identity Services Engine Sensitive Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-34765MEDIUMCisco Nexus Insights Authenticated Information Disclosure VulnerabilityEPSS 0.9%CVE-2021-40126MEDIUMCisco Umbrella Email Enumeration VulnerabilityEPSS 0.9%CVE-2022-20920HIGHCisco IOS and IOS XE Software SSH Denial of Service VulnerabilityEPSS 0.9%CVE-2019-1948MEDIUMCisco Webex Meetings Mobile (iOS) SSL Certificate Validation VulnerabilityEPSS 0.9%CVE-2020-3154MEDIUMCisco Cloud Web Security SQL Injection VulnerabilityEPSS 0.9%CVE-2025-20354CRITICALCisco Unified Contact Center Express Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-20051MEDIUMCisco Packet Data Network Gateway IPsec ICMP Denial of Service VulnerabilityEPSS 0.9%CVE-2025-20186HIGHA vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authentEPSS 0.9%CVE-2025-20184MEDIUMCisco Secure Email and Web Manager and Secure Web Appliance Command Injection VulnerabilityEPSS 0.9%CVE-2020-3126LOWCisco Webex Meetings Multimedia Viewer VulnerabilityEPSS 0.9%CVE-2019-1701MEDIUMCisco Adaptive Security Appliance and Firepower Threat Defense Software WebVPN Cross-Site Scripting VulnerabilitiesEPSS 0.9%CVE-2018-15426—Cisco Unity Connection Stored Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2023-20020HIGHA vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended EPSS 0.9%CVE-2023-20046HIGHA vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevatEPSS 0.9%CVE-2019-1609MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)EPSS 0.9%CVE-2024-20436HIGHA vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticEPSS 0.9%CVE-2022-20766MEDIUMCisco ATA 190 Series Analog Telephone Adapter firmware Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.9%CVE-2025-20165HIGHCisco BroadWorks SIP Denial of Service VulnerabilityEPSS 0.9%CVE-2011-2054MEDIUMCisco ASA Secondary Authentication Bypass VulnerabilityEPSS 0.9%