Cisco Security Advisories · April 2023 — Cisco Security Advisories
19 advisories 46 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2023-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-staros-ssh-privesc-BmWeJC3h

Cisco PSIRTCoalition ESS < 30%HIGH2023-04-19

Cisco StarOS Software Key-Based SSH Authentication Privilege Escalation Vulnerability

CVEs:CVE-2023-20046

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-193199 affected Cisco
CVRFPID-292523 affected Cisco
Upstream advisory

cisco-sa-rv-stored-xss-vqz7gC8W

Cisco PSIRTCoalition ESS < 30%HIGH2023-04-05

Cisco Small Business RV016, RV042, RV042G, RV082 , RV320, and RV325 Routers Cross-Site Scripting Vulnerabilities

CVEs:CVE-2023-20137CVE-2023-20138CVE-2023-20139CVE-2023-20140CVE-2023-20141CVE-2023-20142CVE-2023-20143CVE-2023-20144CVE-2023-20145CVE-2023-20146CVE-2023-20147CVE-2023-20148CVE-2023-20149CVE-2023-20150CVE-2023-20151

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
Upstream advisory

cisco-sa-duo-replay-knuNKd

Cisco PSIRTCoalition ESS < 30%HIGH2023-04-05

Cisco Duo Authentication for macOS and Duo Authentication for Windows Logon Offline Credentials Replay Vulnerability

CVEs:CVE-2023-20123

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-290489 affected Cisco
Upstream advisory

cisco-sa-adeos-MLAyEcvk

Cisco PSIRTCoalition ESS < 30%HIGH2023-04-05

Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities

CVEs:CVE-2023-20121CVE-2023-20122

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111903 affected Cisco
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.