Cisco Security Advisories · January 2024 — Cisco Security Advisories
10 advisories 14 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2024-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-cucm-rce-bWNzQcUm

Cisco PSIRTActive exploitation (sightings)HIGH2024-01-24

Cisco Unified Communications Products Remote Code Execution Vulnerability

CVEs:CVE-2024-20253

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
CVRFPID-233658 affected Cisco
CVRFPID-244955 affected Cisco
CVRFPID-277610 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-7500 affected Cisco
CVRFPID-88444 affected Cisco
CVRFPID-92631 affected Cisco
Upstream advisory

cisco-sa-broadworks-xss-6syj82Ju

Cisco PSIRTActive exploitation (sightings)HIGH2024-01-10

Cisco BroadWorks Application Delivery Platform and Xtended Services Platform Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20270

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-282087 affected Cisco
Upstream advisory

cisco-sa-ISE-XSS-bL4VTML

Cisco PSIRTActive exploitation (sightings)HIGH2024-01-10

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20251

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111903 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.