Cisco Security Advisories · January 2025 — Cisco Security Advisories
6 advisories 8 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2025-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-xwork-xss-KCcg7WwU

Cisco PSIRTActive exploitation (sightings)HIGH2025-01-08

Cisco Crosswork Network Controller Stored Cross-Site Scripting Vulnerabilities

CVEs:CVE-2025-20123

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-273559 affected Cisco
Upstream advisory

cisco-sa-clamav-ole2-H549rphA

Cisco PSIRTCoalition ESS < 30%HIGH2025-01-22

ClamAV OLE2 File Format Decryption Denial of Service Vulnerability

CVEs:CVE-2025-20128

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-221075 affected Cisco
CVRFPID-292706 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.