Cisco Security Updates – 18 July 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products.

The addressed vulnerabilities could allow the attacker to change the password of the users including administrative users, bypass security restrictions, perform spoofing attacks, cause denial of service attacks, elevate privileges to root, redirect the users to a malicious web page, obtain sensitive credential information, execute arbitrary commands/codes, upload arbitrary files, and gain access to the affected system.

Sample of the addressed vulnerabilities:

1. Cisco Smart Software Manager On-Prem Password Change Vulnerability (CVE-2024-20419):

  • CVSS: 10
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

2. Cisco Secure Email Gateway Arbitrary File Write Vulnerability (CVE-2024-20401):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privilege Required: None
  • User Interaction: None
  • Consequences: Gain Access

Sample of the affected products:

  • Cisco Secure Email Gateway.
  • Cisco SSM On-Prem.
  • Cisco Smart Software Manager Satellite (SSM Satellite).
  • Cisco AsyncOS for Secure Web Appliance.
Vulnerabilities
  • CVE-2024-6387
  • CVE-2024-3596
  • CVE-2024-20456
  • CVE-2024-20435
  • CVE-2024-20429
  • CVE-2024-20419
  • CVE-2024-20416
  • CVE-2024-20401
  • CVE-2024-20400
  • CVE-2024-20396
  • CVE-2024-20395
  • CVE-2024-20323
  • CVE-2024-20296
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Updates

References