Cisco Alert
3006Warning Date
Severity Level
Warning Number
Target Sector
19 May, 2022
● Medium
2022-4853
All
Cisco has released security updates to address several vulnerabilities in the following products:
- Cisco Secure Network Analytics
- Cisco Expressway Series
- Cisco TelePresence VCS
- Cisco ECE
- Cisco CSPC Software
- Cisco UCS Director
Remote attacker could exploit these vulnerabilities by doing the following:
- Read sensitive information
- Execute arbitrary code
- Cross-site scripting (XSS)
The CERT team encourages users to review Cisco security advisory and apply the necessary updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-UCS-XSS-uQSME3L7
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-multi-xss-tyDFjhwb
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-strd-xss-BqFXO9D2
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-bsFVwueV
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-stealth-rce-2hYb9KFK