CVE-2025-20314
- EPSS 0.15%
- Veröffentlicht 24.09.2025 18:15:35
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute persistent code at boot time and break the chain of tr...
CVE-2025-20160
- EPSS 0.44%
- Veröffentlicht 24.09.2025 18:15:34
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the s...
CVE-2025-20240
- EPSS 0.27%
- Veröffentlicht 24.09.2025 18:15:34
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper saniti...
CVE-2025-20293
- EPSS 0.19%
- Veröffentlicht 24.09.2025 18:15:34
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote attacker to access the public-key infrastructure (PKI) server that is runni...
CVE-2025-20311
- EPSS 0.19%
- Veröffentlicht 24.09.2025 18:15:34
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This v...
CVE-2025-20312
- EPSS 0.35%
- Veröffentlicht 24.09.2025 18:15:34
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to impr...
CVE-2025-20149
- EPSS 0.11%
- Veröffentlicht 24.09.2025 18:15:33
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due...
CVE-2025-20334
- EPSS 0.47%
- Veröffentlicht 24.09.2025 17:15:40
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient input valida...
CVE-2025-20253
- EPSS 0.45%
- Veröffentlicht 14.08.2025 16:29:43
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a DoS condition. This vu...
CVE-2025-20239
- EPSS 0.59%
- Veröffentlicht 14.08.2025 16:29:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticate...