Cisco informuje o nowych podatnościach. (P25-136)

cert.pse-online.pl 9 godzin temu

7 maja 2025 r. firma Cisco opublikowała ostrzeżenia dotyczące bezpieczeństwa, mające na celu wyeliminowanie luk w zabezpieczeniach wielu produktów. Zawarto aktualizacje dla następujących produktów:

  • Routery Integrated Services Series 1000
  • Routery Integrated Services Series 1100 (ISR)
  • Routery Integrated Services Series 4000
  • Zintegrowane punkty dostępowe (AP) w routerach Integrated Service Router (ISR)1100 (Wi-Fi 6)
  • Platformy brzegowe Catalyst Series 8200
  • Platformy brzegowe Catalyst Series 8300
  • Platformy brzegowe Catalyst Series 8500
  • Platformy brzegowe Catalyst Series 8500L
  • Kontrolery bezprzewodowe Catalyst 9800-CL do chmury
  • Wbudowany kontroler bezprzewodowy Catalyst 9800 do przełączników Catalyst Series 9300, 9400 i 9500
  • Kontrolery bezprzewodowe Catalyst Series 9800
  • Wbudowany kontroler bezprzewodowy w punktach dostępowych Catalyst 9100X
  • Catalyst SD-WAN Manager – wersje 20.8 i poprzednie, 20.9, 20.10, 20.11, 20.12, 20.13, 20.14, 20.15 i 20.16
  • Moduł wtykowy Wi-Fi 6 dla routerów Catalyst IR1800 Rugged Series
  • Przełączniki Cisco Industrial Ethernet serii 2000, 4000, 4010 i 5000
  • Oprogramowanie Cisco IOS, IOS XE, NX-OS i IOS XR
  • Oprogramowanie Cisco Adaptive Security Appliance (ASA)
  • Oprogramowanie Cisco Firepower Threat Defense (FTD)
Link/OpisKrytycznośćCVE ID
Cisco IOS XE Wireless Controller Software Arbitrary File Upload VulnerabilityKrytycznaCVE-2025-20188
Cisco IOS XE Software for WLC Wireless IPv6 Clients Denial of Service VulnerabilityWysokaCVE-2025-20140
Cisco IOS XE Software Web-Based Management Interface Command Injection VulnerabilityWysokaCVE-2025-20186
Cisco IOS, IOS XE, and IOS XR Software TWAMP Denial of Service VulnerabilityWysokaCVE-2025-20154
Multiple Cisco Products Switch Integrated Security Features DHCPv6 Denial of Service VulnerabilityWysokaCVE-2025-20191
Cisco Catalyst SD-WAN Manager Privilege Escalation VulnerabilityWysokaCVE-2025-20122
Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software, IOS Software, and IOS XE Software IKEv2 Denial of Service VulnerabilityWysokaCVE-2025-20182
Cisco IOS XE Software Privilege Escalation VulnerabilitiesWysokaCVE-2025-20197
CVE-2025-20198 …
Cisco IOS XE Software Internet Key Exchange Version 1 Denial of Service VulnerabilityWysokaCVE-2025-20192
Cisco IOS XE Software DHCP Snooping Denial of Service VulnerabilityWysokaCVE-2025-20162
Cisco IOS Software Industrial Ethernet Switch Device Manager Privilege Escalation VulnerabilityWysokaCVE-2025-20164
Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol Denial of Service VulnerabilityWysokaCVE-2025-20202
Cisco Catalyst Center Unauthenticated API Access VulnerabilityWysokaCVE-2025-20210
Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass VulnerabilityWysokaCVE-2025-20181
Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers ARP Denial of Service VulnerabilityWysokaCVE-2025-20189
Cisco IOS XE Software Web-Based Management Interface VulnerabilitiesŚredniaCVE-2025-20193
CVE-2025-20194 …
Cisco Catalyst SD-WAN Manager Stored Cross-Site Scripting VulnerabilityŚredniaCVE-2025-20147
Cisco Catalyst SD-WAN Manager Reflected HTML Injection VulnerabilityŚredniaCVE-2025-20216
Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction VulnerabilityŚredniaCVE-2025-20151
Cisco IOS XE SD-WAN Software Packet Filtering Bypass VulnerabilityŚredniaCVE-2025-20221
Cisco Catalyst SD-WAN Manager Arbitrary File Creation VulnerabilityŚredniaCVE-2025-20187
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite VulnerabilityŚredniaCVE-2025-20213
Cisco IOS XE Software Model-Driven Programmability Authorization Bypass VulnerabilityŚredniaCVE-2025-20214
Cisco IOS Software on Cisco Catalyst 1000 and 2960L Switches Access Control List Bypass VulnerabilityŚredniaCVE-2025-20137
Cisco IOx Application Hosting Environment Denial of Service VulnerabilityŚredniaCVE-2025-20196
Cisco IOS XE Wireless Controller Software Unauthorized User Deletion VulnerabilityŚredniaCVE-2025-20190
Cisco Catalyst Center Insufficient Access Control VulnerabilityŚredniaCVE-2025-20223
Cisco Catalyst SD-WAN Manager Certificate Validation VulnerabilityŚredniaCVE-2025-20157
Cisco IOS XE Software Bootstrap Arbitrary File Write VulnerabilityŚredniaCVE-2025-20155
Idź do oryginalnego materiału