Cisco fixes multiple vulnerabilities in its products
Cisco has released security updates to address multiple vulnerabilities in Cisco products.
Cisco has updated security advisory to address high severity vulnerability (CVE-2022-20681) in Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers. An attacker could exploit this vulnerability to elevate privileges on an affected device.
Cisco has also updated security advisory to address medium severity vulnerabilities (CVE-2022-20677, CVE-2022-20718, CVE-2022-20719, CVE-2022-20720, CVE-2022-20721, CVE-2022-20722, CVE-2022-20723, CVE-2022-20724, CVE-2022-20725, CVE-2022-20726, CVE-2022-20727) in the Cisco IOx application hosting environment on multiple Cisco platforms. An attacker could exploit the flaws to inject arbitrary commands, execute arbitrary code, install applications , or conduct a cross-site scripting (XSS) attack on affected system.
Details on all of the addressed vulnerabilities are available on Cisco’s security portal - cisco.com.
16 May 2022