Cisco Alert
2783Warning Date
Severity Level
Warning Number
Target Sector
5 May, 2022
● High
2022-4780
All
Cisco has released security updates to address several vulnerabilities in the following products:
- TelePresence CE Software
- RoomOS Software in Cloud-Aware On-Premises operation
- Secure Endpoint, formerly Advanced Malware Protection (AMP) for Endpoints - Linux
- Secure Endpoint, formerly AMP for Endpoints - MacOS
- Secure Endpoint, formerly AMP for Endpoints - Windows
- ClamAV scanning library
- 0.103.5 and earlier
- 0.104.2 and earlier
- Cisco Small Business RV Series Routers
- RV340 Dual WAN Gigabit VPN Routers
- RV340W Dual WAN Gigabit Wireless-AC VPN Routers
- RV345 Dual WAN Gigabit VPN Routers
- RV345P Dual WAN Gigabit POE VPN Routers
- Cisco SD-WAN vManage Software
- Cisco Enterprise NFVIS
Remote attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Read sensitive information
- Execute arbitrary code
The CERT team encourages users to review Cisco security advisory and apply the necessary updates:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ROS-DOS-X7H7XhkK
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-ZAZBwRVG
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-prVGcHLd
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-vL9x58p4
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-html-XAuOK8mR
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbrv-rce-OYLQbL9u
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-rv-cmd-inj-8Pv9JMJD
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmge-infodc-WPSkAMhp
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9