OpenSSL Vulnerabilities Impact Multiple Cisco Products
Cisco confirms that IoT Field Network Director and Operational Insights Collector are impacted by buffer overflow vulnerabilities in OpenSSL
Summary
Cisco confirms that IoT Field Network Director and Operational Insights Collector are impacted by buffer overflow vulnerabilities in OpenSSL
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has confirmed that their product IoT Field Network Director is impacted by OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786. The vulnerabilities could be exploited by a malicious attacker to cause a denial-of-service condition or to facilitate remote code execution on an affected system.
Threat updates
| Date | Update |
|---|---|
| 24 Nov 2022 |
Cisco updates vulnerable products list
Cisco has updated their vulnerable products to include the Operational Insights Collector. This article has been updated to reflect those changes. |
Remediation advice
Affected organisations should review Cisco Advisory cisco-sa-openssl-W9sdCc2a and apply the relevant update.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 24 November 2022 12:48 pm