Cisco Releases Security Updates for Multiple Products
Six advisories address two Critical, three High and fourteen Medium impact vulnerabilities affecting multiple products
Summary
Six advisories address two Critical, three High and fourteen Medium impact vulnerabilities affecting multiple products
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Please review the Cisco Security Advisories for more information about these and many more affected platforms.
Threat details
Introduction
Cisco has released six security advisories addressing nineteen vulnerabilities effecting multiple Cisco products. These include two advisories addressing a medium and two critical vulnerabilities in the Cisco Hyperflex HX product. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
Cisco also released an advisory about products effected by two OpenSSL vulnerabilities released in March 2021. You can read more about this OpenSSL vulnerability by reading CC-3801. Exploitation of these vulnerabilities could allow an attacker to use a valid non-certificate authority (CA) certificate to act as a CA and sign a certificate for an arbitrary organization, user or device, or to cause a denial of service (DoS) condition.
Exploitation of CVE-2021-1497 and CVE-2021-1498
Cisco advises of active exploitation of HyperFlex HX Command Injection Vulnerabilities referred to as CVE-2021-1497 and CVE-2021-1498.
Threat updates
| Date | Update |
|---|---|
| 23 Dec 2022 |
Cisco advises of active exploitation of HyperFlex HX vulnerabilities
Cisco advises of active exploitation of HyperFlex HX Command Injection Vulnerabilities referred as CVE-2021-1497 and CVE-2021-1498. This article has been updated to reflect those changes. |
| 23 Dec 2022 |
Updated the format of the article
This article has been updated to align with the format of articles that are now released. |
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates.
Remediation steps
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 23 December 2022 1:41 pm