Cisco Releases Security Updates for Multiple Products
Scheduled updates for Cisco products address one vulnerability rated as Critical impact and three rated as High impact
Summary
Scheduled updates for Cisco products address one vulnerability rated as Critical impact and three rated as High impact
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released security updates to address vulnerabilities in multiple products, with one update rated as Critical and one update rated as High. The critical update addresses an arbitrary code execution vulnerability in the Cisco Nexus Dashboard.
The updates rated as high relate to cross-site request forgery, a container image read/write vulnerability, and an SSL certificate validation vulnerability in Cisco Nexus Dashboard. A remote, unauthenticated attacker could exploit some of these vulnerabilities to take control of an affected system.
Other scheduled updates address an additional 41 vulnerabilities rated as Medium.
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco Nexus Dashboard Unauthorized Access Vulnerabilities https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndb-mhcvuln-vpsBPJ9y |
| Patch |
Cisco Nexus Dashboard SSL Certificate Validation Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-tlsvld-TbAQLp3N |
CVE Vulnerabilities
Last edited: 21 July 2022 2:38 pm