Cisco Alert
3210Warning Date
Severity Level
Warning Number
Target Sector
9 November, 2022
● High
2022-5353
All
Cisco has released security updates to address several vulnerabilities in the following products:
- Cisco Adaptive Security Appliance (ASA) Software
- dynamic access policies (DAP)
- Simple Network Management Protocol (SNMP)
- Cisco FirePOWER Software - FirePOWER Module
- Cisco Secure Firewalls 3100 - Secure boot implementation
- SSL/TLS client
- Firepower Threat Defense (FTD)
- Dynamic access policies (DAP)
- Simple Network Management Protocol (SNMP)
- Software SSH
- Generic routing encapsulation (GRE)
- Cisco Secure Firewalls 3100 - Secure boot implementation
- SSL/TLS client
- Cisco Firepower Management Center (FMC)
- Software SSH
- Cisco Firepower Management Center (FMC) Software
- Simple Network Management Protocol (SNMP)
- Cisco Next-Generation Intrusion Prevention System (NGIPS) Software
- Simple Network Management Protocol (SNMP)
An attacker could exploit these vulnerabilities by doing the following:
- Remote Denial of Service attack (DoS)
- Bypass the secure boot functionality with physical access
- Perform an SNMP GET request using a default credential.
The CERT team encourages users to review Cisco security advisory and apply the necessary updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssl-client-dos-cCrQPkA
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fw3100-secure-boot-5M8mUh26
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-gre-dos-hmedHQPM
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcsfr-snmp-access-6gqgtJ4S
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-dos-OwEunWJN
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-snmp-dos-qsqBNM6x
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-dap-dos-GhYZBxDU