Cisco Releases Security Updates for Multiple Products
Scheduled update addresses two High and three Medium impact vulnerabilities
Summary
Scheduled update addresses two High and three Medium impact vulnerabilities
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco have released multiple security updates to address two High and three Medium vulnerabilities in multiple products. The first High vulnerability affects Meraki MX and Meraki Z3 Teleworker Gateway devices, which an attacker could exploit by crafting a malicious request and creating a denial-of-service condition.
The second High vulnerability affecting Identity Services Engine (ISE) concerns unauthorised file access, and it could be exploited by an attacker by sending a specially crafted HTTP request, allowing the attacker to read or delete specific files. There are also three other Medium severity advisories.
An unauthenticated, remote attacker could exploit some of these vulnerabilities to take control of a system.
Remediation advice
Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Cisco Meraki MX and Z3 Teleworker Gateway VPN Denial of Service Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-mx-vpn-dos-vnESbgBf |
| Patch |
Cisco Identity Services Engine Unauthorized File Access Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM |
| Patch |
Cisco Jabber Client Software Extensible Messaging and Presence Protocol Stanza Smuggling Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-xmpp-Ne9SCM |
| Patch |
Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-trav-beFvCcyu |
| Patch |
Cisco Identity Services Engine Cross-Site Scripting Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-twLnpy3M |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 20 October 2022 2:04 pm