Cisco Releases Security Updates for Multiple Products
Scheduled updates for Cisco products
Summary
Scheduled updates for Cisco products
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released security updates to address vulnerabilities in multiple products, with one update rated as Critical and two rated as High by Cisco. The Critical update addresses vulnerabilities relating to arbitrary write privileges and command injection, and the two High updates relate to privilege escalation and denial-of-service vulnerabilities. A remote, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities - cisco-sa-expressway-filewrite-87Q5YRk https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk |
| Patch |
Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure Privilege Escalation Vulnerability - cisco-sa-uccsmi-prvesc-BQHGe4cm https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccsmi-prvesc-BQHGe4cm |
| Patch |
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability - cisco-sa-ise-dos-JLh9TxBp https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-JLh9TxBp |
CVE Vulnerabilities
Last edited: 4 March 2022 11:51 am