Skip to main content

Cisco Releases Security Updates for Multiple Products

Scheduled updates for Cisco products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Cisco products


Threat details

Introduction

Cisco has released security updates to address vulnerabilities in multiple products, with one update rated as Critical and two rated as High by Cisco. The Critical update addresses vulnerabilities relating to arbitrary write privileges and command injection, and the two High updates relate to privilege escalation and denial-of-service vulnerabilities.  A remote, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates or workarounds.


Remediation steps

Type Step
Patch

Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities - cisco-sa-expressway-filewrite-87Q5YRk


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk
Patch

Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure Privilege Escalation Vulnerability - cisco-sa-uccsmi-prvesc-BQHGe4cm


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccsmi-prvesc-BQHGe4cm
Patch

Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability - cisco-sa-ise-dos-JLh9TxBp


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-JLh9TxBp

Last edited: 4 March 2022 11:51 am