Cisco released security updates for multiple products
Cisco has released security updates to address vulnerabilities in multiple Cisco products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. Dangerous vulnerability was fixed in the web-based management interface of Cisco Prime Infrastructure and Evolved Programmable Network (EPN) Manager that could allow an authenticated, remote attacker to execute arbitrary commands on an affected system - CVE-2021-1487.
One more dangerous vulnerability was fixed in the web UI of Cisco Modeling Labs that could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling Labs server – CVE-2021-1531.
More information on vulnerabilities and updates is available in Cisco security advisories - cisco.com.
21 May 2021