Cisco Alert
2780Warning Date
Severity Level
Warning Number
Target Sector
21 April, 2022
● High
2022-4697
All
Description:
Cisco has released security warnings to address several vulnerabilities in the following products,mainly:
- Cisco Umbrella Virtual Appliance
- Cisco TelePresence Collaboration Endpoint and RoomOS Software
- Cisco Virtualized Infrastructure Manager
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and apply the necessary mitigations and updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uva-static-key-6RQTRs4c
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ce-roomos-dos-c65x2Qf2
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vim-privesc-T2tsFUf
- Cisco Webex Meetings Cross-Site Scripting Vulnerability
- Cisco Adaptive Security Appliance and Cisco Firepower Threat Defense Software AnyConnect SSL VPN Denial of Service Vulnerability
- Cisco Umbrella Secure Web Gateway File Decryption Bypass Vulnerability
- Cisco Unified Communications Products Arbitrary File Read Vulnerability
- Cisco Unified Communications Products Denial of Service Vulnerability
- Cisco Unified Communications Products Cross-Site Request Forgery Vulnerability
- Cisco Unified Communications Manager IM & Presence Service SQL Injection Vulnerability
- Cisco Unified Communications Products Cross-Site Scripting Vulnerability
- Cisco Unified Communications Products Arbitrary File Write Vulnerability
- Cisco IOS XR Software Border Gateway Protocol Ethernet VPN Denial of Service Vulnerability