Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 部落格

訂閱

Cisco Critical Advisories for September Includes Patch for Struts Vulnerability

Cisco has released advisories for 29 issues, including three critical vulnerabilities. The update also includes a patch for CVE-2018-11776 in Apache Struts.

背景說明

On Wednesday, September 5, Cisco released security advisories for 29 issues, rating three of them as critical. One of these critical vulnerabilities is the Apache Struts vulnerability (CVE-2018-11776) that we wrote about last month. The other two critical vulnerabilities affect Cisco’s Umbrella API (CVE-2018-0435) and several Cisco wireless VPN devices (CVE-2018-0423).

Vulnerability details

While exploitation of the Struts vulnerability is the same as reported in our previous blog, this advisory indicates that the Cisco Identity Services Engine (ISE) is affected.

The Cisco Umbrella API vulnerability, when exploited, could allow an authenticated remote attacker to read and modify data. This vulnerability has already been patched by Cisco and no user action is required.

By exploiting the third critical vulnerability in Cisco wireless VPN devices, a remote attacker sending malicious requests to vulnerable devices can trigger a buffer overflow, which could lead to a Denial of Service (DoS) or execution of arbitrary code. In order to exploit this vulnerability, both the remote management interface and Guest account features must be enabled. However, both of these features are disabled by default.

Urgently required actions

For Cisco ISE users, the related bug and patch information can be found here.

For users with affected Cisco wireless VPN devices, we recommend users update to the latest version of the firmware for the devices, which can be found in Cisco’s software center.

找出受影響的系統

Tenable has released the following plugins related to these advisories.

Plugin ID

Description

112219

Cisco Identity Services Engine Struts2 Namespace Vulnerability


Get more information

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

相關文章

您可以利用的網路安全最新消息

輸入您的電子郵件,就不會錯過來自 Tenable 專家提供的及時警示與安全指引。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

除了阿拉伯聯合大公國外,在世界各地建立的 Tenable Vulnerability Management 試用版均包含 Tenable Lumin 及 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,能夠以無與倫比的準確性查看和追蹤所有資產。

除了阿拉伯聯合大公國外,在世界各地建立的 Tenable Vulnerability Management 試用版均包含 Tenable Lumin 及 Tenable Web App Scanning。

Tenable Vulnerability Management

享受現代、雲端型的弱點管理平台,使您能夠以無與倫比的準確性查看和追蹤所有資產。 立即訂閱一年。

100 項資產

選取您的訂閱選項:

立即購買