{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aciscosecure_firewall_threat_defense7.2.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.1.0.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.0.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.3:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.5.2:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.6:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.7:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.0:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1.1:*:*:*:*:*:*:*","cpe:2.3:a:cisco:secure_firewall_threat_defense:7.3.1.2:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.0se:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.0sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.1se:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.1sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.2se:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.2sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.3se:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.3sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.4sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.5sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.6sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.7sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.8sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.9sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.10sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.2.11sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.3.0se:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.3.0sg:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.3.0sq:*:*:*:*:*:*:*","cpe:2.3:o:cisco:ios_xe:3.3.1se:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.3,"id":"CVE-2024-20412"},{"cvss":6.7,"id":"CVE-2024-20413"},{"cvss":6.5,"id":"CVE-2024-20414"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Industrial Ethernet 1000 Series Switches"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","industrial-control-systems","network-security"],"_cs_type":"advisory","_cs_vendors":["Cisco"],"content_html":"\u003cp\u003eCisco has disclosed multiple security vulnerabilities affecting the Industrial Ethernet 1000 Series Switches. These vulnerabilities reside within the web management interface of the devices. An unauthenticated, remote attacker can exploit these flaws to either trigger a denial-of-service (DoS) condition, causing the device to crash or become unresponsive, or execute cross-site scripting (XSS) attacks against an authenticated user's session. These issues (CVE-2024-20412, CVE-2024-20413, and CVE-2024-20414) impact the integrity and availability of network infrastructure. Defenders should prioritize patching or restricting access to the management interfaces of these industrial switches, as they are often critical components in operational technology environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to service outages in industrial control networks or facilitate session hijacking via XSS. Such impacts may disrupt critical OT processes or allow further unauthorized access if administrative credentials are compromised through the web interface.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConsult the official Cisco security advisory for the affected firmware versions and apply the necessary updates to the Cisco Industrial Ethernet 1000 Series Switches.\u003c/li\u003e\n\u003cli\u003eRestrict access to the device web management interface to trusted management networks or internal subnets only.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate industrial switch management interfaces from general-purpose or untrusted network segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T13:11:46Z","date_published":"2026-08-20T13:11:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cisco-ie1000-vulns/","summary":"Cisco Industrial Ethernet 1000 Series Switches contain multiple vulnerabilities, including CVE-2024-20412, CVE-2024-20413, and CVE-2024-20414, which allow unauthenticated attackers to cause a denial-of-service or perform cross-site scripting attacks.","title":"Multiple Vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches","url":"https://feed.craftedsignal.io/briefs/2026-08-cisco-ie1000-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cisco:secure_firewall_threat_defense:7.2.3:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}