Cisco Alert
2477Warning Date
Severity Level
Warning Number
Target Sector
27 September, 2023
● Critical
2023-5814
All
Description:
Cisco has released security updates to address multiple vulnerabilities in the following products:
- Cisco Catalyst SD-WAN Manager
- Cisco IOS XE Software Web UI
- Cisco IOS XE Software for ASR 1000 Series Aggregation Services Routers IPv6 Multicast
- Cisco IOS XE Software Layer 2 Tunneling Protocol
- Cisco DNA Center API
- Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Series Switches
- Cisco IOS XE Software Application Quality of Experience and Unified Threat Defense
- Cisco IOS and IOS XE Software
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Execute Arbitrary Commands
- Unauthorized Access
- Information Disclosure
- Authentication Bypass
- Denial of Service
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and update the affected products:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-vman-sc-LRLfu2z
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-cmdij-FzZAeXAy
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlre-H93FswRz
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xe-l2tp-dos-eB5tuFmV
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-ins-acc-con-nHAVDRBZ
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cat3k-dos-ZZA4Gb3r
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appqoe-utd-dos-p8O57p5y
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aaascp-Tyj4fEJm