Cisco Security Updates – 17 August 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products.

The addressed vulnerabilities could allow the attacker to gain access, obtain information, perform cross site scripting, or gain elevated privileges on the affected products.

Sample of the addressed vulnerabilities:

1. Cisco Unified Communications Manager SQL Injection (CVE-2023-20211):

  • CVSS: 8.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Data Manipulation

2. Cisco ThousandEyes Enterprise Agent Virtual Appliance Privilege Escalation (CVE-2023-20224):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References