Cisco Updates
3101Warning Date
Severity Level
Warning Number
Target Sector
27 August, 2020
● High
2020-1694
All
Description:
Cisco has released security updates to address several vulnerabilities in the following products:
- Cisco UCS Manager Software
- Cisco FXOS or NX-OS
- Firepower 4100 Series (CSCvt46839)
- Firepower 9300 Security Appliances (CSCvt46839)
- MDS 9000 Series Multilayer Switches (CSCvt46835)
- Nexus 3000 Series Switches (CSCvt39630)
- Nexus 5500 Platform Switches (CSCvt46837)
- Nexus 5600 Platform Switches (CSCvt46837)
- Nexus 6000 Series Switches (CSCvt46837)
- Nexus 7000 Series Switches (CSCvt46835)
- Nexus 9000 Series Switches in standalone NX-OS mode (CSCvt39630)
- UCS 6200 Series Fabric Interconnects (CSCvt46838)
- UCS 6300 Series Fabric Interconnects (CSCvt46838)
- UCS 6400 Series Fabric Interconnects (CSCvt46877)
- Cisco IMC Software
- UCS C-Series and S-Series Servers in standalone mode
- UCS E-Series Servers
- 5000 Series Enterprise Network Compute System (ENCS) Platforms
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Elevate privileges
- Execute arbitrary code
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and apply the necessary updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-cli-dos-GQUxCnTe
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxos-nxos-cfs-dos-dAmnymbd
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-dme-rce-cbE3nhZS
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n3n9k-priv-escal-3QhXJBC
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-mvpn-dos-K8kbCrJp
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxosbgp-nlri-dos-458rG2OQ
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-callhome-cmdinj-zkxzSCY
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nx-os-cli-injection
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-nx-os-cli-execution
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-pim-memleak-dos-tC8eP7uw
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-imc-cmdinject-1896