Cisco has released security updates to address vulnerabilities in multiple Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the following Cisco advisories and apply the necessary updates:
- Industrial Network Director Remote Code Execution Vulnerability cisco-sa-20190605-ind-rce
- Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability cisco-sa-20190605-cucm-imp-dos
- Webex Meetings Server Information Disclosure Vulnerability cisco-sa-20190605-webexmeetings-id
- TelePresence Video Communication Server and Cisco Expressway Series Server-Side Request Forgery Vulnerability cisco-sa-20190605-vcs
- Unified Computing System BIOS Signature Bypass Vulnerability cisco-sa-20190605-ucs-biossig-bypass
- IOS XR Software Secure Shell Authentication Vulnerability cisco-sa-20190605-iosxr-ssh
- Industrial Network Director Stored Cross-Site Scripting Vulnerability cisco-sa-20190605-ind-xss
- Industrial Network Director Cross-Site Request Forgery Vulnerability cisco-sa-20190605-ind-csrf
- Enterprise Chat and Email Cross-Site Scripting Vulnerability cisco-sa-20190605-ece-xss
Please share your thoughts.
We recently updated our anonymous product survey; we'd welcome your feedback.