top of page

A patch has been released by Cisco to fix multiple critical vulnerabilities affecting many products

Writer's picture: Rachel HanlonRachel Hanlon

Description

Cisco has released patch to fix multiple vulnerabilities in cisco products. Successful exploit of critical vulnerabilities can allow a remote unauthenticated attacker to gain control of the affected system as the root user.

Following list provides some important vulnerabilities and its impact with CVE ID:

  • [Critical] - CVE-2021-40119: SSH Keys Vulnerability in Cisco Policy Suite Static can allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installations.

  • [Critical] - CVE-2021-34795: Vulnerability in web-based management interface of the Cisco Catalyst PON Series Switches can allow an attacker to perform command injection, configuration changes and Log in with a default credential if the Telnet protocol is enabled on affected systems. This vulnerability is due to insufficient expiration of session credentials.

  • [High] - CVE-2021-34739: Session Credentials Replay Vulnerability in Cisco Small Business Series Switches can allow an attacker to replay valid user session credentials and gain unauthorized access to web-based management interface with administrator privileges.

  • [High] - CVE-2021-34741: Denial of Service Vulnerability in Cisco Email Security Appliance can allow an attacker to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation of incoming emails.

Recommendations

Workaround:

It is recommended to update cisco products with latest available update/patch.

Reference



Comments


Testimonials

Ibec - For Irish Business

"Ibec engaged with VISO two years ago.  While our primary objective was to improve our information security posture, we were also looking for a long-term partner with expertise and knowledge of the continually evolving cyber landscape. The professionals at VISO are a pleasure to work with and their team is always on hand when we need them."

2-3 Prospect Road, Glasnevin, Dublin 9, D09 K5V2

Telephone: Ireland +353 1 9121331  U.K.  +44 20 30260575

 

We simplify Cyber Security 

Privacy Policy

  • Twitter
  • Facebook
  • LinkedIn

© 2022 proudly created by The Rainbow Vault

ISO 27001 Cyber Security standard_Awarded to VISO Cyber Security
cyberessentials_certification- awarded to VISO Cyber Security
bottom of page