Cisco Vulnerabilities and Affected Products
Vulnerabilities associated with Cisco SD-WAN vEdge Cloud.
Products
Clear product- Cisco Small Business RV Series Router Firmware262 vulnerabilities
- Cisco IOS XE Software248 vulnerabilities
- Cisco Firepower Threat Defense Software161 vulnerabilities
- Cisco Adaptive Security Appliance (ASA) Software160 vulnerabilities
- Cisco Identity Services Engine Software156 vulnerabilities
- Cisco Firepower Management Center128 vulnerabilities
- Cisco IOS XR Software107 vulnerabilities
- Cisco NX-OS Software88 vulnerabilities
- Cisco Data Center Network Manager74 vulnerabilities
- Cisco SD-WAN vManage61 vulnerabilities
- Cisco SD-WAN Solution54 vulnerabilities
- Cisco Unified Communications Manager52 vulnerabilities
- Cisco Prime Infrastructure50 vulnerabilities
- Cisco Secure Firewall Threat Defense (FTD) Software48 vulnerabilities
- Cisco Webex Meetings46 vulnerabilities
- Cisco Catalyst SD-WAN Manager45 vulnerabilities
- IOS41 vulnerabilities
- Cisco Enterprise NFV Infrastructure Software39 vulnerabilities
- Cisco IOS36 vulnerabilities
- Cisco Unified Contact Center Express36 vulnerabilities
- Cisco WebEx WRF Player35 vulnerabilities
- Cisco Digital Network Architecture Center (DNA Center)33 vulnerabilities
- Cisco Unified Computing System (Managed)33 vulnerabilities
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software31 vulnerabilities
- Cisco Unity Connection31 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-20339MEDIUM | Cisco SD-WAN vEdge Software Access Control List Bypass VulnerabilityA vulnerability in the access control list (ACL) processing of IPv4 packets of Cisco SD-WAN vEdge Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the improper enforcement of the implicit deny all at the end of a configured ACL. An attacker could exploit this vulnerability by attempting to send unauthorized traffic to an interface on an affected device. A successful exploit could allow the attacker to bypass an ACL on the affect… CWE-284Sep 24, 2025 | CVSS5.8v3.1 | EPSS0.294% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-26071HIGH | Cisco SD-WAN vEdge Arbitrary File Creation VulnerabilityA vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation for specific commands. An attacker could exploit this vulnerability by including crafted arguments to those specific commands. A successful exploit could allow the attacker to create or overwrite arbitrary files on the… CWE-22Nov 18, 2024 | CVSS8.4v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-20496MEDIUM | Cisco SD-WAN vEdge Routers Denial of Service VulnerabilityA vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to incorrect handling of a specific type of malformed UDP packet. An attacker in a machine-in-the-middle position could exploit this vulnerability by sending crafted UDP packets to an affected device. A successful exploit could allow the attacker to cause the device to re… CWE-787Sep 25, 2024 | CVSS6.1v3.1 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-20775HIGH | Cisco SD-WAN Software Privilege Escalation VulnerabilityA vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. The… | CVSS7.8v3.1 | EPSS12.5% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |