Cisco Updates
3196Warning Date
Severity Level
Warning Number
Target Sector
3 October, 2019
● High
2019-486
All
Description:
Cisco has released security updates to address multiple vulnerabilities in the following products:
- Cisco Adaptive Security Appliance (ASA)
- Cisco Firepower Threat Defense (FTD)
- Cisco Unified Communications Manager
- Pluggable Authentication Module (PAM)
- Advanced Malware Protection (AMP)
- IC3000 Industrial Compute Gateway
- Cisco Firepower Management Center (FMC)
- Cisco Security Manager
- Firepower System Software Detection Engine
- Unified Contact Center Express (UCCX)
- Identity Services Engine (ISE)
- Cisco Prime Infrastructure
- Cisco Unified Communications Manager Session Management Edition (SME)
Threats:
Remote attacker could exploit these vulnerabilities by doing the following:
- Increased CPU utilization.
- Denial of service attack (DoS).
- Cross-site scripting attack (XSS).
- Cross-site request forgery attack (CSRF).
- Bypass the file and malware inspection policies.
- Bypass security restrictions.
- Execute arbitrary commands on the underlying operating system (OS) of an affected device as administrative or root.
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and apply the necessary updates: https://tools.cisco.com/security/center/publicationListing.x