Security News > 2023 > April > Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products
![Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products](/static/build/img/news/cisco-and-vmware-release-security-updates-to-patch-critical-flaws-in-their-products-medium.jpg)
Cisco and VMware have released security updates to address critical security flaws in their products that could be exploited by malicious actors to execute arbitrary code on affected systems.
The most severe of the vulnerabilities is a command injection flaw in Cisco Industrial Network Director, which resides in the web UI component and arises as a result of improper input validation when uploading a Device Pack.
While there are workarounds that plug the security hole, Cisco cautions customers to test the effectiveness of such remediations in their own environments before administering them.
VMware Aria Operations for Logs 8.12 fixes this vulnerability along with a high-severity command injection flaw that could allow an attacker with admin privileges to run arbitrary commands as root.
The alert comes almost three months after VMware plugged two critical issues in the same product that could result in remote code execution.
With Cisco and VMware appliances turning out to be lucrative targets for threat actors, it's recommended that users move quickly to apply the updates to mitigate potential threats.
News URL
https://thehackernews.com/2023/04/cisco-and-vmware-release-security.html
Related news
- Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management (source)
- Critical security hole in Apache Struts under exploit (source)
- Vanir: Open-source security patch validation for Android (source)
- BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products (source)
- Patch Alert: Critical Apache Struts Flaw Found, Exploitation Attempts Detected (source)
- Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now (source)
- The ongoing evolution of the CIS Critical Security Controls (source)
- Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks (source)
- 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now (source)
- Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9) (source)