Skip to main content

Cisco Releases Security Update for Secure Web Appliance

Scheduled update addresses one High vulnerability

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled update addresses one High vulnerability


Affected platforms

The following platforms are known to be affected:

Threat details

This vulnerability affects Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), both virtual and hardware appliances.

Cisco has confirmed that this vulnerability does not affect the following Cisco products:

  • Email Security Appliance (ESA), both virtual and hardware appliances
  • Secure Email and Web Manager, formerly Security Management Appliance (SMA), both virtual and hardware appliances

Introduction

Cisco has released a security update to address a vulnerability rated as High. The vulnerability affects Cisco Secure Web Appliance and could allow an authenticated, remote attacker to perform a command injection and escalate privileges to root. An attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review the following Cisco Security Advisory and apply the necessary updates.


Remediation steps

Type Step
Patch

Cisco Secure Web Appliance Privilege Escalation Vulnerability | cisco-sa-wsa-prv-esc-8PdRU8t8


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-8PdRU8t8


Last edited: 19 August 2022 3:05 pm