Cisco Updates
3205Warning Date
Severity Level
Warning Number
Target Sector
17 October, 2019
● High
2019-531
All
Description:
Foxit has released security update to address multiple vulnerabilities in the following products:
- Cisco Aironet Access Points (APs): 1540 - 1560 - 1800 - 2800 - 3800
- Cisco Firepower Management Center (FMC): earlier than 6.5.0
- Cisco Identity Services Engine (ISE) earlier than 2.4.0 Patch 10
- Cisco Small Business Smart and Managed Switches
- Cisco SPA100 Series Analog Telephone Adapters (ATAs) 1.4.1 SR3 and earlier
- Cisco SPA122 ATA with Router Devices 1.4.1 SR3 and earlier
- Cisco TelePresence Collaboration Endpoint (CE) earlier than 9.8.1
- Cisco TelePresence Video Communication Server (VCS) X12.5.4 and later
- Cisco Wireless LAN Controller (WLC) earlier than 8.10
- Cisco Aironet and Catalyst 9100 Access Points (APs)
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Remote cross-site scripting (XSS) attack.
- Read tcpdump files of ISE generated on an affected device remotely.
- Cross-site request forgery (CSRF) attack.
- Access ATAs sensitive information remotely.
- View the contents of arbitrary files on ATAs.
- Command injections.
- Denial of service attack (DoS).
- Execute arbitrary code on CE as a root.
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and apply the necessary updates: https://tools.cisco.com/security/center/publicationListing.x