Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Cisco

25,873 known vulnerabilities

289
CRITICAL
1,422
HIGH
2,148
MEDIUM
17
LOW

Top Products

ios xe 395 secure firewall threat defense 271 nx-os 184 adaptive security appliance software 178 secure firewall management center 172 ios 167 identity services engine 164 rv130w 131 rv130w firmware 130 rv110w firmware 130
3,877 CVEs · Page 11/78
8.4
CVE-2024-20489

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attac

7.2
CVE-2024-20483

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s

7.4
CVE-2024-20406

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci

8.8
CVE-2024-20398

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write fi

5.3
CVE-2024-20390

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attac

8.8
CVE-2024-20381

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use

5.5
CVE-2024-20343

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the

7.4
CVE-2024-20317

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergen

8.6
CVE-2024-20304

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen

5.5
CVE-2024-20503

A vulnerability in Cisco Duo Epic for Hyperdrive could allow an authenticated, local attacker to view sensitive informat

4.3
CVE-2024-20497

A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as a

6.0
CVE-2024-20469

A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local att

7.5
CVE-2024-20440

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive inf

9.8
CVE-2024-20439 KEV

A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a

6.5
CVE-2024-20478

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco

5.3
CVE-2024-20286

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at

5.3
CVE-2024-20285

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at

5.3
CVE-2024-20284

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at

4.3
CVE-2024-20279

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (

6.5
CVE-2024-20486

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic

6.5
CVE-2024-20466

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.5
CVE-2024-20417

Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote at

6.1
CVE-2024-20488

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni

8.6
CVE-2024-20375

A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unifi

4.8
CVE-2024-20479

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond

9.8
CVE-2024-20454

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco

7.5
CVE-2024-20451

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco

9.8
CVE-2024-20450

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco

5.4
CVE-2024-20443

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to cond

8.8
CVE-2024-20435

A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to exe

6.5
CVE-2024-20429

A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authentic

10.0
CVE-2024-20419

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth

9.8
CVE-2024-20401

A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unau

4.7
CVE-2024-20400

A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote

5.3
CVE-2024-20396

A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain acce

6.4
CVE-2024-20395

A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacke

7.5
CVE-2024-20323

A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the

4.7
CVE-2024-20296

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat

6.7
CVE-2024-20456

A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv

6.0
CVE-2024-20399 KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator cred

4.8
CVE-2024-20405

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t

7.2
CVE-2024-20404

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t

8.8
CVE-2024-20360

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an

5.8
CVE-2024-20363

Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that

5.8
CVE-2024-20361

A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC)

5.0
CVE-2024-20355

A vulnerability in the implementation of SAML 2.0 single sign-on (SSO) for remote access VPN services in Cisco Adaptive

5.8
CVE-2024-20293

A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software an

5.8
CVE-2024-20261

A vulnerability in the file policy feature that is used to inspect encrypted archive files of Cisco Firepower Threat Def

7.8
CVE-2024-20389

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated

7.8
CVE-2024-20326

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated

Frequently Asked Questions

How many CVEs affect Cisco?

Cisco has 25,873 CVE records in our database, including 1527 critical and 12515 high severity vulnerabilities. 90 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Cisco vulnerabilities?

Cisco has 1527 critical severity (CVSS 9.0+) and 12515 high severity (CVSS 7.0-8.9) vulnerabilities. 90 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Cisco vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Cisco products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Cisco Vulnerabilities

CyberStrike scans your infrastructure for Cisco vulnerabilities and provides real-time remediation guidance.

Get Started