Cisco Alert
3035Warning Date
Severity Level
Warning Number
Target Sector
7 April, 2022
● Medium
2022-4630
All
Description:
Cisco has released security warnings to address several vulnerabilities in the following products:
- Cisco Web Security Appliance
- Cisco Webex Meetings Java
- Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware
- Cisco Web Security Appliance Filter
- Cisco Secure Network Analytics Network Diagrams Application
- Cisco Identity Services Engine
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Cross-site scripting (XSS)
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and apply the necessary mitigations and updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-stored-xss-XPsJghMY
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-java-MVX6crH9
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voip-phone-csrf-K56vXvVx
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-swa-filter-bypass-XXXTU3X
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sna-xss-mCA9tQnJ
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-info-exp-YXAWYP3s
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ESA-SNMP-JLAJksWK