<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 14:01:44 +0000</lastBuildDate>
    <item>
      <title>bdu:2018-00497</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2018-00497</link>
      <description>bdu:2018-00497</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2018-00497</guid>
    </item>
    <item>
      <title>certfr-2018-avi-156 — De multiples vulnérabilités ont été découvertes dans les produits Cisco.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-156</link>
      <description>certfr-2018-avi-156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-156</guid>
    </item>
    <item>
      <title>cisco-sa-20180328-xesc — Cisco IOS XE Software Static Credential Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-20180328-xesc</link>
      <description>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot.&#13;
&#13;
The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xesc [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xesc&amp;#34;]&#13;
This advisory is part of the March 28, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 20 Cisco Security Advisories that describe 22 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-66682&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot.&#13;
&#13;
The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
This advisory is available at the following link:&#13;
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xesc [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-xesc&amp;#34;]&#13;
This advisory is part of the March 28, 2018, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which includes 20 Cisco Security Advisories that describe 22 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: March 2018 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication [&amp;#34;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-66682&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-20180328-xesc</guid>
    </item>
    <item>
      <title>cnvd-2018-07315</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-07315</link>
      <description>cnvd-2018-07315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-07315</guid>
    </item>
    <item>
      <title>EUVD-2026-205404</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-205404</link>
      <description>EUVD-2026-205404</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-205404</guid>
    </item>
    <item>
      <title>fkie_cve-2018-0150</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-0150</link>
      <description>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-0150</guid>
    </item>
    <item>
      <title>GHSA-wpq9-4577-qx62</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wpq9-4577-qx62</link>
      <description>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wpq9-4577-qx62</guid>
    </item>
    <item>
      <title>gsd-2018-0150</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-0150</link>
      <description>gsd-2018-0150</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-0150</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1871 — Cisco IOS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1871</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco IOS und Cisco IOS XE ausnutzen, um Daten zu manipulieren, vertrauliche Daten einzusehen, einen Denial of Service Angriff durchzuführen, seine Privilegien zu erweitern, Cross-Site Scripting Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen oder beliebigen Code mit administrativen Privilegien zur Ausführung zu bringen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Cisco IOS und Cisco IOS XE ausnutzen, um Daten zu manipulieren, vertrauliche Daten einzusehen, einen Denial of Service Angriff durchzuführen, seine Privilegien zu erweitern, Cross-Site Scripting Angriffe durchzuführen, Sicherheitsmechanismen zu umgehen oder beliebigen Code mit administrativen Privilegien zur Ausführung zu bringen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1871</guid>
    </item>
  </channel>
</rss>
