Cisco Releases Security Patches for New Vulnerabilities Impacting Multiple Products

Share:

Cisco on Wednesday rolled out patches to address three security flaws affecting its products, including a high-severity weakness disclosed in shoppingmode NVIDIA Data Plane Development Kit (MLNX_DPDK) late last month.

Tracked as CVE-2022-28199 (CVSS score: 8.6), the vulnerability stems from a lack of proper error handling in DPDK’s network stack, enabling a remote adversary to trigger a denial-of-service (DoS) condition and cause an impact on data integrity and confidentiality.

“If an error condition is observed on the device interface, the device may either reload or fail to receive traffic, resulting in a denial-of-service (DoS) condition,” Cisco said in a notice published on September 7.

DPDK refers to a set of libraries and optimized network interface card (NIC) drivers for fast packet processing, offering a framework and common API for high-speed networking applications.

Cisco said it investigated its product lineup and determined the following services to be affected by the bug, prompting the networking equipment maker to release software updates –

  • Cisco Catalyst 8000V Edge Software
  • Adaptive Security Virtual Appliance (ASAv), and
  • Secure Firewall Threat Defense Virtual (formerly FTDv)

Aside from CVE-2022-28199, Cisco has also resolved a vulnerability in its Cisco SD-WAN vManage Software that could “allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system.”

The company blamed the shortcoming – assigned the identifier CVE-2022-20696 (CVSS score: 7.5) – on the absence of “sufficient protection mechanisms” in the messaging server container ports. It credited Orange Business for reporting the vulnerability.

Successful exploitation of the flaw could permit the attacker to view and inject messages into the messaging service, which can cause configuration changes or cause the system to reload, Cisco said.

A third flaw remediated by Cisco is a vulnerability in the messaging interface of Cisco Webex App (CVE-2022-20863, CVSS score: 4.3), which could enable an unauthenticated, remote attacker to modify links or other content and conduct phishing attacks.

“This vulnerability exists because the affected software does not properly handle character rendering,” it said. “An attacker could exploit this vulnerability by sending messages within the application interface.”

Cisco credited Rex, Bruce, and Zachery from Binance Red Team for discovering and reporting the vulnerability.

Lastly, it also disclosed details of an authentication bypass bug (CVE-2022-20923, CVSS score: 4.0) affecting Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers, which it said will not be fixed owing to the products reaching end-of-life (EOL).

“Cisco has not released and will not release software updates to address the vulnerability,” the company noted, encouraging users to “migrate to Cisco Small Business RV132W, RV160, or RV160W Routers.”

Cisco Releases Security Patches for New Vulnerabilities Impacting Multiple Products (thehackernews.com)

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:10 pm, Jul 8, 2025
weather icon 23°C
L: 22° | H: 25°
clear sky
Humidity: 38 %
Pressure: 1018 mb
Wind: 8 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:53 am
Sunset: 9:17 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 7 mph 40 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 0.16 mm 16% 8 mph 58 % 1022 mb 0 mm/h
Thu Jul 10 10:00 pm
weather icon
18° | 30°°C 0 mm 0% 11 mph 76 % 1024 mb 0 mm/h
Fri Jul 11 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 8 mph 65 % 1022 mb 0 mm/h
Sat Jul 12 10:00 pm
weather icon
19° | 29°°C 0 mm 0% 10 mph 65 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
23° | 23°°C 0 mm 0% 7 mph 38 % 1017 mb 0 mm/h
Today 7:00 pm
weather icon
24° | 24°°C 0 mm 0% 7 mph 35 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
19° | 20°°C 0 mm 0% 4 mph 40 % 1018 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 50 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 58 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
16° | 16°°C 0 mm 0% 4 mph 51 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 58 % 1022 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,987.25
0.49%
Ethereum(ETH)
€2,206.70
0.95%
Tether(USDT)
€0.85
0.02%
XRP(XRP)
€1.95
-1.46%
Solana(SOL)
€129.57
-0.57%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.145524
0.24%
Shiba Inu(SHIB)
€0.000010
0.92%
Pepe(PEPE)
€0.000009
0.68%
Scroll to Top