Cisco Products Multiple Vulnerabilities
RISK: High Risk
TYPE: Clients - Productivity Products
Multiple vulnerabilities were identified in Cisco products, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, obtain sensitive information, cross-site scripting and bypass security restriction on the targeted system.
[Updated 30-June-2021] CVE-2020-3580 is being exploited in the wild. Risk level has been escalated to high risk.
Impact
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Cisco Firepower Threat Defense Software
- Cisco Firepower Management Center Software
- Cisco Firepower 1000 Series
- Cisco Firepower 2100 Series
- Cisco Firepower 4110 Series
- Cisco Adaptive Security Appliance Software
- Cisco FXOS Software
Please refer to the link below for detail:
https://tools.cisco.com/security/center/publicationListing.x
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Apply fixes issued by the vendor:
https://tools.cisco.com/security/center/publicationListing.x
Vulnerability Identifier
- CVE-2020-3118
- CVE-2020-3317
- CVE-2020-3299
- CVE-2020-3304
- CVE-2020-3352
- CVE-2020-3373
- CVE-2020-3410
- CVE-2020-3436
- CVE-2020-3455
- CVE-2020-3456
- CVE-2020-3457
- CVE-2020-3458
- CVE-2020-3459
- CVE-2020-3499
- CVE-2020-3514
- CVE-2020-3515
- CVE-2020-3528
- CVE-2020-3529
- CVE-2020-3533
- CVE-2020-3549
- CVE-2020-3550
- CVE-2020-3553
- CVE-2020-3554
- CVE-2020-3555
- CVE-2020-3557
- CVE-2020-3558
- CVE-2020-3561
- CVE-2020-3562
- CVE-2020-3563
- CVE-2020-3564
- CVE-2020-3565
- CVE-2020-3572
- CVE-2020-3577
- CVE-2020-3578
- CVE-2020-3580
- CVE-2020-3581
- CVE-2020-3582
- CVE-2020-3583
- CVE-2020-3585
- CVE-2020-3599
- CVE-2020-27124
Source
Related Link
- https://tools.cisco.com/security/center/publicationListing.x
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-xss-multiple-FCB3vPZe
- https://www.auscert.org.au/bulletins/ESB-2020.3634/
- https://www.auscert.org.au/bulletins/ESB-2020.3637/
- https://www.auscert.org.au/bulletins/ESB-2020.3640/
- https://www.auscert.org.au/bulletins/ESB-2020.3641/
- https://www.auscert.org.au/bulletins/ESB-2020.3643/
- https://www.auscert.org.au/bulletins/ESB-2020.3645/
- https://www.auscert.org.au/bulletins/ESB-2020.3644/
- https://www.auscert.org.au/bulletins/ESB-2020.3647/
- https://www.auscert.org.au/bulletins/ESB-2020.3646/
- https://www.auscert.org.au/bulletins/ESB-2020.3642.3
Related Tags
Share with