Cisco Amplia l’Ambito delle Patch su Voice, Switch e IoT
L’ultimo advisory di Cisco amplia il raggio d’impatto oltre una singola linea di prodotto. I nuovi problemi trasformano Unity Connection in un punto di esecuzione a livello root e in un pivot SSRF, e consentono al traffico SNMP malformato di riavviare gli switch SG350 e SG350X, quindi il rischio reale è la compromissione del management plane e l’interruzione del servizio, non solo un altro bug ad alta gravità.
Cisco Security Advisory: Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on or conduct server-side request forgery (SSRF) attacks through an affected device.