cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
156
Views
0
Helpful
2
Replies

New software versions in Cisco Vulnerability Repository ?

rieda
Level 1
Level 1

How can I search for newer software versions in the Cisco Vulnerability Repository,
or how should I read the information in the Cisco Vulnerability Repository?

In the Cisco Vulnerability Repository, I can check for vulnerabilities for specific software versions.
But what if I have a higher version than the one listed in the repository?
Can I add new versions, or should I search for the highest version in the repository and, if that version is not affected by this vulnerability, then the newer versions are also not affected?

If someone could explain this to me, please.

Thanks in advance,
Alex

 

2 Replies 2

shambhu.kumar
Spotlight
Spotlight

Hello rieda,

Most of vulnerabilities are linked with CVE ID and under details of CVE-ID there are bug-ID,  based on Bug-ID you will get details like  "Known Affected Releases " and "Known Fixed Releases " workaround etc.

 

 

wajidhassan
Level 4
Level 4

Hey @rieda,

Each vulnerability is tied to a CVE ID, and that links to a Bug ID on Cisco’s side. Under that Bug ID, you’ll find the "Known Affected Releases" and "Known Fixed Releases." If your version is higher than the fixed release, it means you're not affected.

You don’t need to add versions manually, just use the fixed release as your baseline, and if you're running anything newer, you’re usually covered for that CVE