Vulnerabilità ed exploit · DDoS
Cisco Chiude Dozzina di Vulnerabilità IOS e IOS XE Cisco ha rilasciato patch per una dozzina di vulnerabilità di gravità alta e media in IOS e IOS XE. Quattro difetti pubblicamente divulgati (CVE-2026-20110 , -20112, -20113, -20114) interessano i Catalyst 9300. Due di questi possono essere concatenati per escalation di privilegi. La catena può causare un DoS persistente che in scenari convalidati ha richiesto intervento fisico per il ripristino.
2 fonti · 26 mar
CVE-2026-20113 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.3% (20º percentile).
CVE-2026-20114 NVD KEV
CVSS 5.4 MEDIUM: a vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an… EPSS 0.3% (20º percentile).
CVE-2026-20112 NVD KEV
CVSS 4.8 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.2% (9º percentile).
CVE-2026-20110 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of…
Cronologia Fonti 26 mar SecurityWeek
Cisco Patches Multiple Vulnerabilities in IOS Software
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
originale 25 mar Cisco PSIRT
Cisco Security Advisory: Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
originale 25 mar Cisco PSIRT
Cisco Security Advisory: Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Cisco Chiude Dozzina di Vulnerabilità IOS e IOS XE
Altro da oggi
Vulnerabilità ed exploit · DDoS
Cisco Chiude Dozzina di Vulnerabilità IOS e IOS XE Cisco ha rilasciato patch per una dozzina di vulnerabilità di gravità alta e media in IOS e IOS XE. Quattro difetti pubblicamente divulgati (CVE-2026-20110 , -20112, -20113, -20114) interessano i Catalyst 9300. Due di questi possono essere concatenati per escalation di privilegi. La catena può causare un DoS persistente che in scenari convalidati ha richiesto intervento fisico per il ripristino.
2 fonti · 26 mar
CVE-2026-20113 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.3% (20º percentile).
CVE-2026-20114 NVD KEV
CVSS 5.4 MEDIUM: a vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an… EPSS 0.3% (20º percentile).
CVE-2026-20112 NVD KEV
CVSS 4.8 MEDIUM: a vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE… EPSS 0.2% (9º percentile).
CVE-2026-20110 NVD KEV
CVSS 6.5 MEDIUM: a vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of…
Cronologia Fonti 26 mar SecurityWeek
Cisco Patches Multiple Vulnerabilities in IOS Software
The high- and medium-severity flaws could lead to denial-of-service, secure boot bypass, information disclosure, and privilege escalation.
originale 25 mar Cisco PSIRT
Cisco Security Advisory: Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.
originale 25 mar Cisco PSIRT
Cisco Security Advisory: Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability
A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-03-26
Every edition of this story: Cisco Chiude Dozzina di Vulnerabilità IOS e IOS XE
Altro da oggi