Skip to main content

Cisco Releases Security Updates

Cisco has released updates to address vulnerabilities affecting multiple products. A remote attacker could exploit one of these vulnerabilities to take control of a system.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Cisco has released updates to address vulnerabilities affecting multiple products. A remote attacker could exploit one of these vulnerabilities to take control of a system.

Threat details


Remediation advice

US-CERT encourage users and administrators to review the following Cisco Security Advisories and apply the necessary updates:

Remediation steps

Type Step
  • Elastic Services Controller Unauthorized Access Vulnerability cisco-sa-20170705-esc2
  • Ultra Services Framework UAS Unauthenticated Access Vulnerability cisco-sa-20170705-uas
  • Ultra Services Framework Staging Server Arbitrary Command Execution Vulnerability cisco-sa-20170705-usf3
  • StarOS CLI Command Injection Vulnerability cisco-sa-20170705-asrcmd
  • Elastic Services Controller Arbitrary Command Execution Vulnerability cisco-sa-20170705-esc1
  • Ultra Services Framework AutoVNF Symbolic Link Handling Information Disclosure Vulnerability cisco-sa-20170705-usf1
  • Ultra Services Framework AutoVNF Log File User Credential Information Disclosure Vulnerability cisco-sa-20170705-usf2

Last edited: 17 February 2020 11:28 am