HomeSecurityCisco announces patches for vulnerabilities in IOS XE

Cisco releases patches for IOS XE vulnerabilities

vulnerabilities

Recently, several vulnerabilities were discovered in Cisco Systems' IOS XE operating system. 19 of them were rated as very serious, while the rest were rated as moderate. The company immediately proceeded to create 24 patches to address them, however, there are some vulnerabilities for which patches have not yet been issued. Specifically, the vulnerabilities are found in two business routers RV320 and RV325.

The vulnerabilities in both routers were rated as serious. Patches for the vulnerabilities were released in January. However, the routers are still vulnerable because the company said the patches were not complete. Cisco said that “ firmware to address [these vulnerabilities] are not currently available.”

CVE-2019-1652 is a command injection vulnerability. This bug allows an attacker with administrator privileges to remotely execute arbitrary commands on the affected device.

The second vulnerability, CVE-2019-1653, is an information disclosure vulnerability. This vulnerability affects both routers and allows an attacker to gain access to sensitive information remotely.

Regarding the vulnerabilities in the IOS XE operating system, these are the serious vulnerabilities of privilege escalation, injection and denial of service. Specifically, the CVE-2019-1745 is a command injection vulnerability. As we said above, it can be used to execute arbitrary commands in the operating system.

"The vulnerability is due to insufficient validation of user-supplied commands. An attacker could exploit this vulnerability and gain administrator privileges on the affected device," Cisco wrote.

In addition to patches for vulnerabilities in its products, Cisco also announced the existence of some other critical vulnerabilities. The first was found in Moodle (CVE-2019-3809) and allows a remote attacker to perform a server side request forgery attack. The second security vulnerability (CVE-2019-9948) was found in the Python programming language. The third and fourth vulnerabilities reported by Cisco allow arbitrary code execution in the Elastic Kibana Security Audit Logger (CVE-2019-7610) and the Elastic Kibana Timelion Visualizer (CVE-2019-7609).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS