Cisco Releases Security Updates for Multiple Products
Scheduled updates for Cisco products address 3 vulnerabilities in VIM, Umbrella Virtual Appliance, RoomOS Software, and TelePresence CE Software
Summary
Scheduled updates for Cisco products address 3 vulnerabilities in VIM, Umbrella Virtual Appliance, RoomOS Software, and TelePresence CE Software
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
Cisco RoomOS Software in Cloud-Aware On-Premises operation, which is cloud based, and Cisco TelePresence CE Software if they are running vulnerable releases and have H.323 Mode enabled.
Threat details
Introduction
Cisco has released security updates to address vulnerabilities in multiple products, which include a privilege escalation vulnerability, a static SSH Host Key vulnerability, and a denial of service vulnerability. A remote, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco Virtualized Infrastructure Manager Privilege Escalation Vulnerability | cisco-sa-vim-privesc-T2tsFUf https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vim-privesc-T2tsFUf |
| Patch |
Cisco Umbrella Virtual Appliance Static SSH Host Key Vulnerability | cisco-sa-uva-static-key-6RQTRs4c https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uva-static-key-6RQTRs4c |
| Patch |
Cisco TelePresence Collaboration Endpoint and RoomOS Software H.323 Denial of Service Vulnerability | cisco-sa-ce-roomos-dos-c65x2Qf2 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ce-roomos-dos-c65x2Qf2 |
CVE Vulnerabilities
Last edited: 25 April 2022 4:59 pm