Cisco Alert
2793Warning Date
Severity Level
Warning Number
Target Sector
15 February, 2023
● Critical
2023-5461
All
Cisco has released a security update to address a high vulnerability in the following products:
• Cisco Email Security Appliance (ESA) (both virtual and physical appliances)
• Cisco Secure Email and Web Manager (both virtual and physical appliances)
• Cisco Nexus Dashboard Software
• Secure Endpoint, formerly Advanced Malware Protection (AMP) for Endpoints, for Linux, MacOS, Windows
• Secure Endpoint Private Cloud
• Secure Web Appliance, formerly Web Security Appliance
An attacker could exploit these vulnerabilities by doing the following:
• Remote Code Execution
• Elevation of Privileges
• Denial of Service Attack
The CERT team encourages users to review Cisco security advisory and update the affected products:
• https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-privesc-9DVkFpJ8
• https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndb-dnsdos-bYscZOsu
• https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy