Cisco Security Advisories · October 2022 — Cisco Security Advisories
14 advisories 27 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2022-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-CTT-IVV-4A66Dsfj

Cisco PSIRTActive exploitation (sightings)HIGH2022-10-05

Cisco Touch 10 Devices Insufficient Identity Verification Vulnerability

CVEs:CVE-2022-20793

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-265966 affected Cisco
CVRFPID-278404 affected Cisco
Upstream advisory

cisco-sa-jabber-xmpp-Ne9SCM

Cisco PSIRTCoalition ESS < 30%HIGH2022-10-05

Cisco Jabber Client Software Extensible Messaging and Presence Protocol Stanza Smuggling Vulnerability

CVEs:CVE-2022-20917

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-278016 affected Cisco
Upstream advisory

cisco-sa-NFVIS-ISV-BQrvEv2h

Cisco PSIRTCoalition ESS < 30%HIGH2022-10-05

Cisco Enterprise NFV Infrastructure Software Improper Signature Verification Vulnerability

CVEs:CVE-2022-20929

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-235874 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.