CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2018-0156

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software and Cisco IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0155

Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

Vendor: Cisco

Product: Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-388

CVE-2018-0154

Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0151

Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-8540

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

Vendor: Microsoft

Product: Malware Protection Engine

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6744

Cisco IOS Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6743

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6740

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6739

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6738

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6737

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6736

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6663

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

Required Action:

Apply updates per vendor instructions.

CVE-2017-6627

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2017-12319

Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20