본문 바로가기
취약점 정보

Cisco 제품 보안 업데이트 권고

by TACHYON & ISARC 2025. 5. 30.

개요

Cisco 사는 제품에서 발생하는 취약점에 대한 보안 업데이트를 발표하고, 관련 취약점을 해결하기 위해 최신 버전으로 업데이트할 것을 권고하였다


취약점 정보

Cisco IOS XE Wireless Controller Software 임의 파일 업로드 취약점

CVE-2025-20188

 

Cisco IOS XE Software의 WLC Wireless IPv6 클라이언트 서비스 거부(DoS) 취약점

CVE-2025-20140

 

Cisco IOS XE Software 웹 기반 관리 인터페이스 명령 삽입(command injection) 취약점

CVE-2025-20186

 

Cisco IOS, IOS XE, IOS XR Software TWAMP 서비스 거부(DoS) 취약점

CVE-2025-20154

 

다수의 Cisco 제품 스위치 통합 보안 기능 DHCPv6 서비스 거부 취약점

CVE-2025-20191

 

Cisco Catalyst SD-WAN Manager 권한 상승 취약점

CVE-2025-20122

 

Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software, IOS Software, IOS XE Software IKEv2 서비스 거부(DoS) 취약점

CVE-2025-20182

 

Cisco IOS XE Software 권한 상승 취약점

CVE-2025-20197, CVE-2025-20198, CVE-2025-20199

 

Cisco IOS XE Software 인터넷 키 교환 버전 1 서비스 거부 취약점

CVE-2025-20192

 

Cisco IOS XE Software DHCP Snooping 서비스 거부(DoS) 취약점

CVE-2025-20162

 

Cisco IOS Software Industrial Ethernet Switch Device Manager 권한 상승 취약점

CVE-2025-20164

 

Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol 서비스 거부(DoS) 취약점

CVE-2025-20202

 

Cisco Catalyst Center 인증되지 않은 API 접근 취약점

CVE-2025-20210

 

Cisco Catalyst 2960X, 2960XR, 2960CX, 그리고 3560CX 시리즈 스위치용 Cisco IOS 소프트웨어의 보안 부팅 우회 취약점

CVE-2025-20181

 

Cisco ASR 903 Aggregation Services Routers용 Cisco IOS XE Software의 ARP 서비스 거부(DoS) 취약점

CVE-2025-20189

 

Cisco IOS XE Software 웹 기반 관리 인터페이스 취약점

CVE-2025-20193, CVE-2025-20194, CVE-2025-20195

 

Cisco Catalyst SD-WAN Manager 저장된 크로스 사이트 스크립팅(Cross-Site Scripting) 취약점

CVE-2025-20147

 

Cisco Catalyst SD-WAN Manager 반사된 HTML 삽입(reflected HTML injection) 취약점

CVE-2025-20216

 

Cisco IOS 및 IOS XE Software SNMPv3 구성 제한 취약점

CVE-2025-20151

 

Cisco IOS XE SD-WAN Software 패킷 필터링 우회 취약점

CVE-2025-20221

 

Cisco IOS XE Software 모델 기반 프로그래머빌리티 권한 부여 우회 취약점

CVE-2025-20214

 

Cisco Catalyst 1000 2960L 스위치의 Cisco IOS 소프트웨어에서 접근 제어 목록 우회 취약점

CVE-2025-20137

 

Cisco IOx Application Hosting Environment 서비스 거부(DoS) 취약점

CVE-2025-20196

 

Cisco IOS XE Wireless Controller Software 비인가 사용자 삭제 취약점

CVE-2025-20190

 

Cisco Catalyst Center 접근 제어 불충분 취약점

CVE-2025-20223

 

Cisco Catalyst SD-WAN Manager 인증서 검증 취약점

CVE-2025-20157

 

Cisco IOS XE Software Bootstrap 임의 파일 쓰기 취약점

CVE-2025-20155

 

Cisco Catalyst SD-WAN Manager 임의 파일 덮어쓰기 취약점

CVE-2025-20213

 

Cisco Catalyst SD-WAN Manager 임의 파일 생성 취약점

CVE-2025-20187

 

Cisco Identity Services Engine RADIUS 서비스 거부(Denial of Service) 취약점

CVE-2025-20152

 

Cisco Unified Intelligence Center 권한 상승 취약점

CVE-2025-20113, CVE-2025-20114

 

Cisco Webex Services의 크로스 사이트 스크립팅(Cross-Site Scripting) 취약점

CVE-2025-20246, CVE-2025-20247, CVE-2025-20250

 

Cisco Webex Meetings Services HTTP 캐시 중독 취약점

CVE-2025-20255

 

Cisco Secure Network Analytics Manager 권한 상승 취약점

CVE-2025-20256

 

Cisco Secure Network Analytics Manager API 권한 부여 취약점

CVE-2025-20257

 

Cisco Identity Services 저장된 크로스 사이트 스크립팅(Cross-Site Scripting) 취약점

CVE-2025-20267

 

Cisco Duo Self-Service Portal 명령어 삽입 취약점

CVE-2025-20258

 

Cisco Unified Communications Products 권한 상승 취약점

CVE-2025-20112

 

Cisco Unified Contact Center Enterprise Cloud Connect 접근 제어 불충분 취약점

CVE-2025-20242

 

Cisco Erlang/OTP SSH 서버 측 원격 코드 실행 취약점

CVE-2025-32433

 

참고자료

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-wncd-p6Gvt6HL

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdinj-gVn3OKNC

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-twamp-kV4FHugn

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sisf-dos-ZGwt4DdY

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-priviesc-WCk7bmmt

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-multiprod-ikev2-dos-gPctUqv2

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-privesc-su7scvdp

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-ikev1-dos-XHk3HzFC

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-dhcpsn-dos-xBn8Mtks

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-http-privesc-wCRd5e3

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-cdp-dos-fpeks9K

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-api-nBPZcJCM

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-c2960-3560-sboot-ZtqADrHq

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr903-rsp3-arp-dos-WmfzdvJZ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-multi-ARNHM4v6

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-xhN8M5jt

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-html-inj-GxVtK6zj

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmpv3-qKEYvzsy

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-bypass-HHUVujdn

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-netconf-nacm-bypass-TGZV9pmQ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipsgacl-pg6qfZk

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-dos-95Fqnf7b

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-user-del-hQxMpUDj

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-insec-acc-mtt8EhEb

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catalyst-tls-PqnD5KEJ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootstrap-KfgxYgdh

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-fileoverwrite-Uc9tXWH

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwanarbfile-2zKhKZwJ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-restart-ss-uf986G2Q

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-priv-esc-3Pk96SU4

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-7teQtFn8

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cache-Q4xbkQBG

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-ssti-dPuLqSmZ

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-apiacv-4B6X5ysw

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-stored-xss-Yff54m73

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-ssp-cmd-inj-RCmYrNA

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-kkhZbHR5

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-contcent-insuffacces-ArDOVhN8

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy