Cisco Products Multiple Vulnerabilities
Release Date:
20 Jan 2023
5445
Views
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities were identified in Cisco Systems Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.
Impact
- Security Restriction Bypass
- Information Disclosure
- Data Manipulation
- Elevation of Privilege
System / Technologies affected
- Cisco AsyncOS Software for Cisco ESA
- Internet Protocol Security (IPsec) VPN
- LoRaWAN
- Media Access Control Security (MACsec)
- SD-WAN
- Secure StackWise Virtual
- Secure Unified Communications
- SSL VPN
- Unified CM
- Unified CM SME
- Wireless Personal Area Network (WPAN)
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-npe-hardening-Dkel83jP
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-url-bypass-WbMQqNJh
Vulnerability Identifier
Source
Related Link
- https://www.auscert.org.au/bulletins/ESB-2023.0276
- https://www.auscert.org.au/bulletins/ESB-2023.0275
- https://www.auscert.org.au/bulletins/ESB-2023.0274
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-npe-hardening-Dkel83jP
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-url-bypass-WbMQqNJh
Related Tags
Share with