Cisco Alert
3032Warning Date
Severity Level
Warning Number
Target Sector
3 March, 2022
● Critical
2022-4466
All
Cisco has released security warnings to address several vulnerabilities in the following products:
- Cisco Expressway Series and Cisco TelePresence VCS
- Cisco Ultra Cloud Core SMI
- Cisco ISE configured with RADIUS authentication services
- Cisco StarOS
- ASR 5000 Series Routers
- Ultra Cloud Core - User Plane Function
- Virtualized Packet Core - Distributed Instance (VPC-DI)
- Virtualized Packet Core - Single Instance (VPC-SI)
Attacker could exploit these vulnerabilities by doing the following:
- Arbitrary File Write
- Command Injection
- Denial of service attack (DoS)
The CERT team encourages users to review Apache security advisory and apply the necessary mitigations and updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-staros-cmdinj-759mNT4n
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-JLh9TxBp
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccsmi-prvesc-BQHGe4cm
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk