Cisco Alert
2309Warning Date
Severity Level
Warning Number
Target Sector
16 August, 2023
● High
2023-5734
All
Description:
Cisco has released security updates to address multiple vulnerabilities in the following products:
- Cisco Unified CM and Cisco Unified CM SME
- Affected Cisco Software Platform
- Cisco Duo Device Health Application for Windows
- Secure Endpoint Connector for Linux
- Secure Endpoint Connector for MacOS
- Secure Endpoint Connector for Windows
- Secure Endpoint Private Cloud
- Virtual Appliance installation of Cisco ThousandEyes Enterprise Agent
Threats:
An attacker could exploit these vulnerabilities by doing the following:
- Denial of Service (DoS)
- SQL Injection
- Elevate Privileges
- Path Traversal
Best practice and Recommendations:
The CERT team encourages users to review Cisco security advisory and update the affected products:
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-dos-FTkhqMWZ
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-rNwNEEee
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-injection-g6MbwH2
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-duo-dha-filewrite-xPMBMZAK
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thoueye-privesc-NVhHGwb3