Cisco Security Advisories · November 2024 — Cisco Security Advisories
15 advisories 25 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2024-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-backhaul-ap-cmdinj-R7E28Ecs

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Unified Industrial Wireless Software for Ultra-Reliable Wireless Backhaul Access Point Command Injection Vulnerability

CVEs:CVE-2024-20418

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-280019 affected Cisco
Upstream advisory

cisco-sa-ece-dos-Oqb9uFEv

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Enterprise Chat and Email Denial of Service Vulnerability

CVEs:CVE-2024-20484

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-256410 affected Cisco
CVRFPID-273559 affected Cisco
Upstream advisory

cisco-sa-imp-inf-disc-cUPKuA5n

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Unified Communications Manager IM & Presence Service Information Disclosure Vulnerability

CVEs:CVE-2024-20457

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
Upstream advisory

cisco-sa-cucm-xss-SVCkMMW

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Unified Communications Manager Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20511

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-epnmpi-sxss-yyf2zkXs

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20514

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-esa-wsa-sma-xss-zYm3f49n

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20504

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189789 affected Cisco
CVRFPID-189790 affected Cisco
CVRFPID-189791 affected Cisco
Upstream advisory

cisco-sa-mpp-xss-8tAV2TvF

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco 6800, 7800, 8800, and 9800 Series Phones with Multiplatform Firmware Stored Cross-Site Scripting Vulnerabilities

CVEs:CVE-2024-20533CVE-2024-20534

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-277607 affected Cisco
CVRFPID-277608 affected Cisco
Upstream advisory

cisco-sa-ccmp-sxss-qBTDBZDD

Cisco PSIRTActive exploitation (sightings)HIGH2024-11-06

Cisco Unified Contact Center Management Portal Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2024-20540

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-285014 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.