Cisco Security Advisories · January 2023 — Cisco Security Advisories
14 advisories 19 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2023-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-rv-cmd-exe-n47kJQLE

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco Small Business RV160 and RV260 Series VPN Routers Remote Command Execution Vulnerability

CVEs:CVE-2023-20045

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
Upstream advisory

cisco-sa-bw-dos-HpkeYzp

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Denial of Service Vulnerability

CVEs:CVE-2023-20020

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-282087 affected Cisco
Upstream advisory

cisco-sa-sb-rv-rcedos-7HjP74jD

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers Remote Code Execution and Denial of Service Vulnerability

CVEs:CVE-2023-20007

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
Upstream advisory

cisco-sa-bw-xss-EzqDXqG4

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco BroadWorks Application Delivery Platform, Application Server, and Xtended Services Platform Cross-Site Scripting Vulnerability

CVEs:CVE-2023-20019

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-282087 affected Cisco
Upstream advisory

cisco-sa-cuis-xss-Omm8jyBX

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco Unified Intelligence Center Reflected Cross-Site Scripting Vulnerability

CVEs:CVE-2023-20058

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-198393 affected Cisco
CVRFPID-244955 affected Cisco
CVRFPID-7500 affected Cisco
CVRFPID-92631 affected Cisco
Upstream advisory

cisco-sa-lldp-memlk-McOecPT

Cisco PSIRTCoalition ESS < 30%HIGH2023-01-11

Cisco Webex Room Phone and Cisco Webex Share Link Layer Discovery Protocol Memory Leak Vulnerability

CVEs:CVE-2023-20047

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-278888 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.