Cisco Security Advisories · April 2025 — Cisco Security Advisories
7 advisories 8 CVEs 1 EXPLOITED

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2025-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-erlang-otp-ssh-xyZZy

Cisco PSIRTExploitedCISA KEV listedHIGH2025-04-22

Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025

CVEs:CVE-2025-32433

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-183630 affected Cisco
CVRFPID-189789 affected Cisco
CVRFPID-193199 affected Cisco
CVRFPID-227765 affected Cisco
CVRFPID-235874 affected Cisco
CVRFPID-280785 affected Cisco
CVRFPID-281298 affected Cisco
CVRFPID-284723 affected Cisco
CVRFPID-284929 affected Cisco
CVRFPID-285044 affected Cisco
CVRFPID-286454 affected Cisco
CVRFPID-286462 affected Cisco
CVRFPID-292520 affected Cisco
CVRFPID-292522 affected Cisco
CVRFPID-292682 affected Cisco
Upstream advisory

cisco-sa-epnmpi-sxss-GSScPGY4

Cisco PSIRTActive exploitation (sightings)HIGH2025-04-02

Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerabilities

CVEs:CVE-2025-20120CVE-2025-20203

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.