Your review has been sent successfully

Cisco Updates

2434
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

17 October, 2019

● High

2019-531

All

Description:

Foxit has released security update to address multiple vulnerabilities in the following products:

  • Cisco Aironet Access Points (APs): 1540 - 1560 - 1800 - 2800 - 3800
  • Cisco Firepower Management Center (FMC): earlier than 6.5.0
  • Cisco Identity Services Engine (ISE) earlier than 2.4.0 Patch 10
  • Cisco Small Business Smart and Managed Switches
  • Cisco SPA100 Series Analog Telephone Adapters (ATAs) 1.4.1 SR3 and earlier
  • Cisco SPA122 ATA with Router Devices 1.4.1 SR3 and earlier
  • Cisco TelePresence Collaboration Endpoint (CE) earlier than 9.8.1
  • Cisco TelePresence Video Communication Server (VCS) X12.5.4 and later
  • Cisco Wireless LAN Controller (WLC) earlier than 8.10
  • Cisco Aironet and Catalyst 9100 Access Points (APs)

Threats:

Attacker could exploit these vulnerabilities by doing the following:

  • Remote cross-site scripting (XSS) attack.
  • Read tcpdump files of ISE generated on an affected device remotely.
  • Cross-site request forgery (CSRF) attack.
  • Access ATAs sensitive information remotely.
  • View the contents of arbitrary files on ATAs.
  • Command injections.
  • Denial of service attack (DoS).
  • Execute arbitrary code on CE as a root.

Best practice and Recommendations:

The CERT team encourages users to review Cisco security advisory and apply the necessary updates: https://tools.cisco.com/security/center/publicationListing.x

Last updated at 24 December, 2019

Rate the content

rate-icon
up icon