Security News > 2021 > January > Cisco Patches Critical Vulnerabilities in SD-WAN, DNA Center, SSMS Products

Cisco Patches Critical Vulnerabilities in SD-WAN, DNA Center, SSMS Products
2021-01-21 14:05

Cisco this week released patches to address a significant number of vulnerabilities across its product portfolio, including several critical flaws in SD-WAN products, DNA Center, and Smart Software Manager Satellite.

Several command injection bugs addressed in SD-WAN products could allow an attacker to perform actions as root on the affected devices, the most important of which is rated critical severity, featuring a CVSS score of 9.9.

A critical vulnerability addressed in DNA Center could be exploited to perform command injection attacks.

Cisco DNA Center releases prior to version 1.3.1.0 are affected.

Cisco Smart Software Manager On-Prem releases 6.3.0 and later contain fixes for all of these flaws.

This week, the company also released patches for multiple other high- and medium-severity flaws in SD-WAN, DNA Center, Data Center Network Manager, SSMS, Advanced Malware Protection for Endpoints for Windows and Immunet for Windows, Web Security Appliance, Umbrella, Unified Communications products, Elastic Services Controller, Email Security Appliance, Content Security Management Appliance, and StarOS. Information on all of the addressed vulnerabilities can be found on Cisco's security portal.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/KCju2taJoF0/cisco-patches-critical-vulnerabilities-sd-wan-dna-center-ssms-products

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 2046 21 1771 1669 288 3749