Cisco Products Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Clients - Productivity Products
Multiple vulnerabilities were identified in Cisco products, a remote attacker could exploit some of these vulnerabilities to trigger cross site scripting, denial of service, elevation of privilege, remote code execution, security restriction bypass, sensitive information disclosure and tampering on the targeted system.
Impact
- Cross-Site Scripting
- Denial of Service
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Data Manipulation
System / Technologies affected
- Cisco Small Business Smart and Managed Switches
- Cisco Identity Services Engine (ISE)
- Cisco Unified Communications Manager (Unified CM)
- Cisco Webex Meetings
- Cisco IOS XR
- Cisco AnyConnect
Please refer to the link below for detail:
https://tools.cisco.com/security/center/publicationListing.x
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- Cisco Small Business Smart and Managed Switches
- Cisco Identity Services Engine (ISE)
- Cisco Unified Communications Manager (Unified CM)
- Cisco Webex Meetings
- Cisco IOS XR
- Cisco AnyConnect
Vulnerability Identifier
- CVE-2020-3346
- CVE-2020-3363
- CVE-2020-3412
- CVE-2020-3413
- CVE-2020-3433
- CVE-2020-3434
- CVE-2020-3435
- CVE-2020-3449
- CVE-2020-3472
- CVE-2020-3501
- CVE-2020-3502
- CVE-2020-3525
- CVE-2020-3532
- CVE-2020-10713
Source
Related Link
Share with