Cisco Releases Security Updates
Affected platforms
The following platforms are known to be affected:
Cisco Cloud Services Platform 5000-W Series Versions: any running Virtual Wide Area Application Services (vWAAS) 6.4.5 and earlier
Cisco Enterprise Network Compute System 5400-W Series Versions: any running Virtual Wide Area Application Services (vWAAS) 6.4.5 and earlier
Cisco Smart Software Manager On-Premise Versions: all prior to 8-202004
Cisco Video Surveillance IP Cameras Versions: 8000 series (if running firmware prior to 1.0.9-4 and have Cisco Discovery Protocol enabled)
Threat details
Introduction
Cisco has released security updates to address vulnerabilities in Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Users and administrators are encouraged to review the following Cisco Advisories and apply the relevant updates:
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco vWAAS for Cisco ENCS 5400-W Series and CSP 5000-W Series Default Credentials Vulnerability | https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-waas-encsw-cspw-cred-hZzL29A7 |
| Patch |
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability | https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smart-priv-esca-nqwxXWBu |
| Patch |
Cisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Remote Code Execution and Denial of Service Vulnerabilities | https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipcameras-rce-dos-uPyJYxN3 |
Last edited: 24 August 2020 1:28 pm