Cisco Releases May 2025 IOS XE Software Security Advisory Bundled Publication


Cisco has released 20 security advisories that describe 26 vulnerabilities in Cisco IOS Software and Cisco IOS XE Software. Cisco IOS (internetwork operating system) is the operating system used on Networking devices. Cisco IOS XE is a modular version of that operating system, used on newer enterprise networking devices. Cisco has released software updates that address these vulnerabilities. One critical and two high severity vulnerabilities are highlighted below.

  • CVE-2025-20188 has a CVSSv3 score of 10.0 and is within the out-of-band access point download feature. If successfully exploited, a remote unauthenticated attacker could upload arbitrary files to an affected system.

Read more…
Source: NHS Digital


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Months after NSA disclosed Microsoft cert bug, datacenters remain unpatched

    January 26, 2023

    Most Windows-powered datacenter systems and applications remain vulnerable to a spoofing bug in CryptoAPI that was disclosed by the NSA and the UK National Cyber Security Center (NCSC) and patched by Microsoft last year, according to Akamai’s researchers. CryptoAPI helps developers secure Windows-based apps using cryptography; the API can be used, for instance, to validate certificates ...

  • New wave of attacks use ProxyNotShell/OWASSRF vulnerabilities to target Microsoft Exchange

    January 24, 2023

    Researchers at S.C. Bitdefender SRL today warned of a new wave of attacks using known vulnerabilities to target Microsoft Exchange. The researchers started to notice an increase in attacks using ProxyNotShell/OWASSRF exploits to target on-premises Microsoft Exchange deployments at the end of November. The Server-Side Request Forgery attacks allow an attacker to send a crafted request ...

  • Apple fixes actively exploited iOS zero-day on older iPhones, iPads

    January 23, 2023

    Apple has backported security patches addressing a remotely exploitable zero-day vulnerability to older iPhones and iPads. This bug is tracked as CVE-2022-42856, and it stems from a type confusion weakness in Apple’s Webkit web browser browsing engine. Read more… Source: Bleeping Computer  

  • CISA Adds One Known Exploited Vulnerability to Catalog

    January 23, 2023

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses a significant risk to the federal enterprise. Note: To view the newly added vulnerabilities in the catalog, click on the arrow in the ...

  • Exploiting null-dereferences in the Linux kernel

    January 19, 2023

    For a fair amount of time, null-deref bugs were a highly exploitable kernel bug class. Back when the kernel was able to access userland memory without restriction, and userland programs were still able to map the zero page, there were many easy techniques for exploiting null-deref bugs. However with the introduction of modern exploit mitigations such ...

  • Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475)

    January 19, 2023

    Mandiant is tracking a suspected China-nexus campaign believed to have exploited a recently announced vulnerability in Fortinet’s FortiOS SSL-VPN, CVE-2022-42475, as a zero-day. Evidence suggests the exploitation was occurring as early as October 2022 and identified targets include a European government entity and a managed service provider located in Africa. Mandiant identified a new malware they ...