Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Goat Feed · Topic

    #cisco

    Items tagged #cisco

    Back to the daily feed
    criticalKEVBGC-RS 4.7Infra · likely in-scope

    CISA KEV: Cisco IOS CVE-2008-4128 (CVSS 3.1 4.3 MEDIUM) - IOS Cross-Site Request Forgery Vulnerability

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

    criticalKEVBGC-RS 4.2Infra · likely in-scope

    CISA KEV: Cisco Catalyst SD-WAN Manager CVE-2026-20128 - Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

    Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.