Your review has been sent successfully

Cisco Alert

3447
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

28 April, 2022

● High

2022-4741

All

Description:

Cisco has released security updates to address several vulnerabilities in the following products:

  • Cisco Firepower Management Center Software
  • Cisco Firepower Threat Defense Software Local Malware Analysis
  • Cisco Firepower Threat Defense (FTD) Software
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches or Cisco Catalyst 9000 Family Wireless Controllers:
    • Catalyst 9300 Series Switches
    • Catalyst 9400 Series Switches
    • Catalyst 9500 Series Switches
    • Catalyst 9600 Series Switches
    • Catalyst 9800 Embedded Wireless Controllers for Catalyst 9300, 9400, and 9500 Series Switches
    • Catalyst 9800 Series Wireless Controllers
    • Catalyst 9800-CL Wireless Controllers for Cloud
    • Embedded Wireless Controllers on Catalyst Access Points
Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Denial of service attack (DoS)
  • Information Disclosure
  • Cross-site scripting (XSS)
  • Bypass the Security Intelligence DNS feed
  • XML injection
  • Privilege Escalation
  • Read or modify data within an IPsec IKEv2 VPN tunnel remotely
  • Upload malicious files to the affected system
Best practice and Recommendations:

The CERT team encourages users to review Cisco security advisory and apply the necessary updates:

Last updated at 28 April, 2022

Rate the content

rate-icon
up icon