Cisco Products Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in Cisco products, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and sensitive information disclosure on the targeted system.
Notes: No patch is currently available.
[Updated on 2020-07-24]
Note: Patch is currently available. The risk level was decreased to medium risk correspondingly.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Cisco ASR 5000
- Cisco ASR 5500
- Cisco Virtual Packet Core
Please refer to the link below for detail:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- Cisco ASR 5000 21.5.27
- Cisco ASR 5500 21.5.27
- Cisco ASR 5500 21.11.15
- Cisco ASR 5500 21.14.22
- Cisco ASR 5500 21.20.2
- Cisco Virtual Packet Core 21.5.27
- Cisco Virtual Packet Core 21.11.15
- Cisco Virtual Packet Core 21.14.22
- Cisco Virtual Packet Core 21.20.2
Please refer to the link below for detail:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC
Vulnerability Identifier
- CVE-2020-11896
- CVE-2020-11897
- CVE-2020-11898
- CVE-2020-11899
- CVE-2020-11900
- CVE-2020-11901
- CVE-2020-11902
- CVE-2020-11903
- CVE-2020-11904
- CVE-2020-11905
- CVE-2020-11906
- CVE-2020-11907
- CVE-2020-11908
- CVE-2020-11909
- CVE-2020-11910
- CVE-2020-11911
- CVE-2020-11912
- CVE-2020-11913
- CVE-2020-11914
Source
Related Link
Share with