writeups.xyz writeups.xyz / Cisco

Title Vulnerabilities Programs Authors
Phantom Secrets: Undetected Secrets Expose Major Corporations
CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM
Multiple vulnerabilities in Cisco Unified Communications Manager version 11.5.1
SMTP Smuggling - Spoofing E-Mails Worldwide
Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)
CVE-2022-20942: It's not old functionality, it's vintage
SSD Advisory – Cisco Secure Manager Appliance jwt_api_impl Hardcoded JWT Secret Elevation of Privilege
SSD Advisory – Cisco Secure Manager Appliance remediation_request_utils SQL Injection Remote Code Execution
Layer 2 network security bypass using VLAN 0, LLC/SNAP headers and invalid length
Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software
Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling
Advisory: Cisco Small Business RV Series Routers Web Filter Database Update Command Injection Vulnerability
Bug: Cisco IOS SNMPv3 ACL Issues
Blinding Snort: Breaking The Modbus OT Preprocessor
Multiple Vulnerabilities in Cisco Expressway
Pwning a Cisco RV340 with a 4 bug chain exploit
Unauthenticated Remote Code Execution in Cisco Nexus Dashboard Fabric Controller (formerly DCNM)
Advisory: Cisco RV340 Dual WAN Gigabit VPN Router (RCE over LAN)
flashback_connects (Cisco RV340 SSL VPN Unauthenticated Remote Code Execution as root)
Weaponizing Middleboxes for TCP Reflected Amplification
Advisory: Cisco RV34X Series – Authentication Bypass and Remote Command Execution
SD-PWN — Part 3 — Cisco vManage — Another Day, Another Network Takeover
Pentesting Cisco SD-WAN Part 2: Breaking Routers
Pentesting Cisco SD-WAN Part 1: Attacking vManage