Cisco Security Advisories · November 2021 — Cisco Security Advisories
20 advisories 26 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2021-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-cucm-path-trav-dKCvktvO

Cisco PSIRTCoalition ESS < 30%HIGH2021-11-03

Cisco Unified Communications Products Path Traversal Vulnerability

CVEs:CVE-2021-34701

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-277610 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-CSPC-ILR-8qmW8y8X

Cisco PSIRTCoalition ESS < 30%HIGH2021-11-17

Cisco Common Services Platform Collector Improper Logging Restriction Vulnerability

CVEs:CVE-2021-40130

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-257214 affected Cisco
Upstream advisory

cisco-sa-CSPC-XSS-KjrNbM3p

Cisco PSIRTCoalition ESS < 30%HIGH2021-11-17

Cisco Common Services Platform Collector Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2021-40131

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-257214 affected Cisco
Upstream advisory

cisco-sa-pi-epnm-xss-U2JK537j

Cisco PSIRTCoalition ESS < 30%HIGH2021-11-03

Cisco Prime Infrastructure and Evolved Programmable Network Manager Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2021-34784

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-ucm-csrf-xrTkDu3H

Cisco PSIRTCoalition ESS < 30%MEDIUM2021-11-03

Cisco Unified Communications Products Cross-Site Request Forgery Vulnerability

CVEs:CVE-2021-34773

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-88444 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.