Skip to main content

Cisco Releases Security Updates for Multiple Products

Scheduled update addresses two High and three Medium impact vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled update addresses two High and three Medium impact vulnerabilities


Threat details

Introduction

Cisco have released multiple security updates to address two High and three Medium vulnerabilities in multiple products. The first High vulnerability affects Meraki MX and Meraki Z3 Teleworker Gateway devices, which an attacker could exploit by crafting a malicious request and creating a denial-of-service condition.

The second High vulnerability affecting Identity Services Engine (ISE) concerns unauthorised file access, and it could be exploited by an attacker by sending a specially crafted HTTP request, allowing the attacker to read or delete specific files. There are also three other Medium severity advisories.

An unauthenticated, remote attacker could exploit some of these vulnerabilities to take control of a system.


Remediation advice

Affected organisations are encouraged to review the following Cisco Security Advisories and apply the necessary updates.


Remediation steps

Type Step
Patch

Cisco Meraki MX and Z3 Teleworker Gateway VPN Denial of Service Vulnerability


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-mx-vpn-dos-vnESbgBf
Patch

Cisco Identity Services Engine Unauthorized File Access Vulnerability


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM
Patch

Cisco Jabber Client Software Extensible Messaging and Presence Protocol Stanza Smuggling Vulnerability


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-xmpp-Ne9SCM
Patch

Cisco TelePresence Collaboration Endpoint and RoomOS Software Vulnerabilities


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-trav-beFvCcyu
Patch

Cisco Identity Services Engine Cross-Site Scripting Vulnerability


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-twLnpy3M


Last edited: 20 October 2022 2:04 pm