Cisco Releases Security Patches for Multiple Products
Scheduled update addresses two High severity vulnerabilities and two Medium severity vulnerabilities
Summary
Scheduled update addresses two High severity vulnerabilities and two Medium severity vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released four security updates to address two vulnerabilities rated as High and two rated as Medium. The two High vulnerabilities are related to unauthenticated access to messaging services in the Cisco SD-WAN vManage Software and a vulnerability in NVIDIA Data Plane Development Kit. An unauthenticated attacker could exploit this vulnerability to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates.
Note: Cisco will not release software updates to address the vulnerability in the Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers as they have entered the end-of-life process.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco SD-WAN vManage Software Unauthenticated Access to Messaging Services Vulnerability | cisco-sa-vmanage-msg-serv-AqTup7vs https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-msg-serv-AqTup7vs |
| Patch |
Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022 | cisco-sa-mlx5-jbPCrqD8 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8 |
| Patch |
Cisco Webex Meetings App Character Interface Manipulation Vulnerability | cisco-sa-webex-app-qrtO6YC2 https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-qrtO6YC2 |
| Guidance |
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers IPSec VPN Server Authentication Bypass Vulnerability | cisco-sa-sb-rv-vpnbypass-Cpheup9O https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 8 September 2022 5:00 pm