Adobe Plugs Gaping Security Holes in Reader, Acrobat

Software maker Adobe on Tuesday shipped patches for at least 56 security vulnerabilities in a wide range of products, some serious enough to expose Windows and macOS users to code execution attacks.

Adobe called special attention to its APSB23-24 bulletin that covers critical-severity security flaws in the widely deployed Adobe Acrobat and Reader software.

“Successful exploitation could lead to arbitrary code execution, privilege escalation, security feature bypass and memory leak,” Adobe said in a warning addressed to both Windows and macOS users. 

The company documented at least 16 vulnerabilities in the Acrobat and Reader updates and said it was not aware of any in-the-wild exploitation. 

Adobe also documented critical-severity code execution flaws in Adobe Digital Editions (Windows) and Adobe InCopy (Windows and macOS).

 The April batch of Patch Tuesday updates also provides cover for 14 documented issues in Adobe Substance 3D Stager (Windows and macOS), some serious enough to lead to arbitrary code execution and memory leak in the context of the current user.

Adobe also rolled out patches for Adobe Dimension (15 critical and important vulnerabilities),  Adobe Substance 3D Designer (9 critical bugs) that expose Windows and macOS users to arbitrary code execution in the context of the current user. 

Related: Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days

Related: Chrome 111 Update Patches High-Severity Vulnerabilities

Related: Samsung Mobile Chipsets Vulnerable to Baseband Code Execution Exploits

Adobe Plugs Gaping Security Holes in Reader, Acrobat




ICS Patch Tuesday: Siemens, Schneider Electric Address Dozens of Vulnerabilities

Siemens and Schneider Electric’s Patch Tuesday advisories for April 2023 address a total of 38 vulnerabilities found in their products. 

The total number of vulnerabilities is significantly smaller than in February and March, when the industrial giants addressed roughly 100 security issues. 

Siemens

Siemens has published 14 new advisories that cover a total of 26 vulnerabilities. Some issues have been patched, but for others only workarounds and mitigations are available, and the company does not plan on releasing fixes for some of the impacted products. 

The most serious appears to be CVE-2023-28489, a critical vulnerability affecting Sicam A8000 series remote terminal units (RTUs), which are designed for telecontrol and automation in the energy supply sector.

The vulnerability can allow an unauthenticated attacker to execute arbitrary commands on the targeted device, but attacks are only possible if the device is configured to allow remote operation, which is disabled by default. Siemens has released patches for this security hole.

Siemens has also informed customers about three high-severity DoS vulnerabilities affecting the web server present in multiple Simatic industrial products. 

Siprotec 5 devices are affected by a DoS vulnerability that can be exploited by an unauthenticated attacker by sending malicious requests to the targeted system.

Several high-severity flaws disclosed by Siemens are related to the parsing of specially crafted files, which can often lead to arbitrary code execution. An attacker can exploit these vulnerabilities by getting a user to open a malicious file.

Impacted products include JT Open Toolkit, JT Utilities, Teamcenter Visualization, JT2Go, and TIA Portal.

[ Read: Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms ] 

Siemens has also informed customers about issues affecting third-party components, including critical and/or high-severity bugs in the Wind River VxWorks real-time operating system, the Linux kernel, OPC Foundation Local Discovery Server (LDS), Luxion’s KeyShot, and various libraries. 

Vulnerable versions of these third-party components are used in products such as Scalance XCM332 switches, Solid Edge, and Simatic products.

Exploitation of these flaws can lead to arbitrary code execution, DoS attacks, privilege escalation, and information disclosure. 

Medium-severity vulnerabilities related to weak encryption and other information-exposure issues have been addressed by Siemens in Scalance X-200IRT, Simatic industrial PCs, Mendix, and the Polarion application lifecycle management (ALM) products.  

Schneider Electric 

Schneider Electric has released six new advisories covering a dozen vulnerabilities. The company has made available patches for most of the flaws and has shared mitigations for the issues it has yet to fix with updates.

The most important advisory, based on CVSS scores, covers two critical and one-high severity vulnerabilities affecting APC and Schneider-branded Easy UPS online monitoring software. Exploitation can lead to remote code execution or a DoS condition. 

Customers have also been informed about a high-severity code execution issue in InsightHome and InsightFacility smart edge devices for solar and storage systems. However, exploitation requires authentication. 

Remote code execution and DoS flaws have been found in the EcoStruxure Control Expert software for Modicon PLCs and PACs. In addition, DoS bugs have been found in some of the Modicon PLCs and PACs themselves. 

Schneider has also informed customers about third-party component vulnerabilities, specifically three high-severity issues affecting its controllers due to the use of Codesys components.

A medium-severity issue that can allow a local attacker to execute code during the installation process has been patched in the Easergy Builder installer for T300, Saitel DR and Saitel DP products.

Related: 2023 ICS Patch Tuesday Debuts With 12 Security Advisories From Siemens, Schneider

Related: Siemens Drives Rise in ICS Vulnerabilities Discovered in 2022: Report

https://www.securityweek.com/ics-patch-tuesday-siemens-schneider-electric-address-dozens-of-vulnerabilities/




Apple Rolls Out Zero-Day Patches to Older iOS, macOS Devices

Apple on Monday released updates for older versions of its iOS and macOS operating systems to patch zero-day vulnerabilities whose existence came to light last week.

The tech giant informed customers on Friday, April 7, that iOS and iPadOS 16.4.1 and macOS Ventura 13.3.1 patch CVE-2023-28206 and CVE-2023-28205, two zero-day vulnerabilities that can be exploited for arbitrary code execution. These updates are designed for the latest iPhones, iPads and Macs. 

CVE-2023-28206 impacts the IOSurfaceAccelerator component and it can allow a malicious application to execute code with kernel privileges. CVE-2023-28205 affects WebKit and it can be exploited by luring the targeted user to a malicious website. 

On Monday, Apple released iOS and iPadOS 15.7.5 to patch the vulnerabilities in iPhone 6s, iPhone 7, iPhone SE and older iPads. It also released macOS Monterey and Big Sur updates to fix CVE-2023-28206. 

The vulnerabilities were reported to Apple by Google’s Threat Analysis Group and Amnesty International’s Security Lab. This suggests that the security holes have likely been exploited by commercial spyware vendors.

Google, Amnesty and Citizen Lab often disclose spyware attacks involving the exploitation of zero-day flaws. 

Apple’s iOS and macOS patches came a week after Google detailed several zero-day and n-day vulnerabilities exploited by commercial spyware vendors to target Android and iOS devices.

The company, which tracks more than 30 spyware vendors, described Chrome, WebKit and kernel driver vulnerabilities exploited in sophisticated attacks whose goal is to hack into the devices of the targeted individuals. 

Related: US to Adopt New Restrictions on Using Commercial Spyware

Related: Apple Patches Actively Exploited WebKit Zero-Day Vulnerability 

Related: Apple Patches Zero-Day Vulnerability Exploited Against iPhones

Related: Apple Says WebKit Zero-Day Hitting iOS, macOS Devices

https://www.securityweek.com/apple-rolls-out-zero-day-patches-to-older-ios-macos-devices/




Microsoft Exchange Server 2013 Reaches End of Support

Microsoft Exchange Server 2013 has reached end of support on April 11, 2023, and will no longer receive security patches.

The product will continue to work even after this date, but Microsoft is no longer providing technical support, bug fixes for usability and stability issues, time zone updates, and, importantly, fixes for vulnerabilities that could expose servers to hacker attacks.

Microsoft reminded users in February about Exchange Server 2013 approaching end of support, advising them to migrate to Exchange 2019 or Exchange Online (Microsoft 365 or Office 365). 

The tech giant has provided detailed instructions for users who have yet to migrate. The company has made no mention about extended support being available. 

It’s important that organizations stop using Exchange 2013 considering that the product has often been targeted in attacks, including by profit-driven cybercriminals and state-sponsored threat actors. 

“Attackers looking to exploit unpatched Exchange servers are not going to go away,” Microsoft warned in January. 

The US Cybersecurity and Infrastructure Security Agency (CISA) is currently aware of 16 Microsoft Exchange vulnerabilities that have been exploited in the wild. The list includes the flaws tracked as ProxyShell and ProxyNotShell.

A variation of ProxyNotShell was exploited in the ransomware attack targeting cloud company Rackspace. 

Despite warnings and high-profile incidents, many organizations fail to install patches, providing attackers with tens of thousands of potential targets to choose from. 

Exchange Server 2013 reached end of support three months after Windows 7 Extended Security Updates (ESU) and Windows 8.1 reached their end of support dates.

Related: Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April

Related: Microsoft Urges Customers to Patch Exchange Servers

Related: Microsoft Confirms Exploitation of Two Exchange Server Zero-Days

https://www.securityweek.com/microsoft-exchange-server-2013-reaches-end-of-support/




Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List

The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch three Veritas Backup Exec vulnerabilities exploited in ransomware attacks.

A data backup product, Veritas Backup Exec supports mixed environments, with support for desktop operating systems, virtual environments (such as VMware and Hyper-V), and cloud platforms (including Amazon S3, Microsoft Azure, and Google Cloud Storage).

Tracked as CVE-2021-27876, CVE-2021-27877, and CVE-2021-27878, the three issues that CISA has added to its ‘Must Patch’ list were disclosed in March 2021, when Veritas released patches.

All three issues were identified in the SHA Authentication scheme of the Veritas Backup Exec agent and could allow an attacker to access arbitrary files or execute arbitrary commands.

In September 2022, a Metasploit module exploiting these vulnerabilities was released, and the first in-the-wild exploitation attempts were observed one month later.

In a report last week, Mandiant warned that the three flaws have been exploited in Alphv (BlackCat) ransomware attacks, for initial access.

According to the cybersecurity firm, there are roughly 8,500 Veritas Backup Exec instances exposed to the internet, some of which might be vulnerable to these flaws.

Last month, Veritas updated its 2021 advisory to warn customers of the observed exploitation attempts: “a known exploit is available in the wild for the vulnerabilities below and could be used as part of a ransomware attack.”

In addition to the Veritas Backup Exec flaws, CISA also added to its Must Patch list CVE-2019-1388, a privilege escalation issue in Microsoft Windows Certificate Dialog, and CVE-2023-26083, an information disclosure bug in Arm Mali GPU kernel driver.

“There is evidence that this vulnerability may be under limited, targeted exploitation. Users are recommended to upgrade if they are impacted by this issue,” Arm noted on March 31.

CISA added the five security defects to its Known Exploited Vulnerabilities catalog on April 7. Per Binding Operational Directive (BOD) 22-01, federal agencies have until April 28 to apply the available patches where necessary.

Related: Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA ‘Must Patch’ List

Related: Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors

Related: CISA Gets Proactive With New Pre-Ransomware Alerts

https://www.securityweek.com/veritas-vulnerabilities-exploited-in-ransomware-attacks-added-to-cisa-must-patch-list/




Most Attack Paths Are Dead Ends, but 2% Lead to Critical Assets: Report

Only 2% of attack paths lead to critical assets. Securing the choke points through which they pass dramatically reduces risk.

Security posture management firm XM Cyber took tens of thousands of attack path assessments involving more than 60 million exposures affecting 20 million entities during 2022, anonymized the datasets and exported them to Cyentia Institute for analysis. The results are presented in its State of Exposure Management in 2023 report (PDF).

The primary findings of the analysis are the sheer volume of exposures (anywhere between 11,000 and 250,000 per month); the number of exposures that are dead ends that cannot be exploited by attackers (75%); and that 2% are located on choke points. A choke point is where multiple attack paths converge on the route to critical assets.

Diagram Description automatically generated

Since it is unrealistic to find and remediate all the exposures, securing the choke points should be a major and important priority. “If your organization is looking for quick wins to reduce considerable risk, these offer compelling focal points,” Zur Ulianitzky, VP of research at XM Cyber, told SecurityWeek. “By focusing on remediating choke points, your organization can practically eliminate all attack paths to critical assets.”

This doesn’t mean that an attacker’s presence can be ignored even on a dead-end path. “Threat actors in the environment can still do considerable damage, even if they don’t have immediate access,” warns Mike Parkin, senior technical engineer at Vulcan Cyber. “If they can gain persistence on a low value target, they have a chance down the line to escalate when a better opportunity presents itself.”

The report has more detailed findings. For example, “Techniques targeting credentials and permissions affect 82% organizations and exploit over 70% of all identified security exposures.” This has been an ongoing issue for years. “It’s also a common misconception that implementing a zero-trust architecture is sufficient to protect against all techniques that exploit forms of trust,” continues the report. “These results, however, make it clear that attackers prey upon trusted administrative services and identities.”

Parkin believes that the onus should be on vendors to distribute products with a secure-by-default configuration. “For users, even the growing use of MFA has only helped where it is deployed correctly,” he adds. “Users are still the greatest challenge in risk management.”

“We know from our own research,” adds Patrick Tiquet, VP of security and architecture at Keeper Security, “that at least a third of organizations leave it to their employees to create and manage their own passwords. In fact, our 2022 US Cybersecurity Census found 30% of the organizations we surveyed don’t even provide guidance and best practices governing passwords and access management.”

The XM Cyber analysis also finds that, “Attackers can access 70% of critical assets in on-prem networks in just 3 steps. It’s even worse in the cloud, where 90% of critical assets are just one hop away from initial compromise.”

Furthermore, “71% of firms have exposures that enable attackers to pivot from their on-prem to cloud environment. Once there, 92% of critical assets lie just one hop away.” The implication is clear – attackers must be kept out of cloud infrastructures, but this cannot be achieved in absentia of protecting the on-prem infrastructure.

“Organizations face tough challenges in managing their diverse on-prem and cloud environments. Part of that struggle stems from failing to consider the big picture and only focusing on each piece in isolation,” adds the report.

When organizations don’t have a consolidated view of the distinct parts of their environment, it’s easy to miss common threads and otherwise obvious attack paths. “The biggest mistake organizations make when managing cloud identities is to attempt to manage them in the same way they did when everyone and everything worked on-prem,” suggests Tiquet. 

However, he disagrees with the report’s downgrading of the importance of zero-trust. “The only realistic way to go about identity management in a cloud-based world is to adopt a zero-trust security model,” he says.

But the overall the statistics cannot lie. “Frankly, organizations can’t realistically remediate all exposures in their environment. Even with the existing prioritization tools the lists are still too long,” says XM Cyber’s Ulianitzky. “Unfortunately, our industry tends to over-rate everything as critical, while offering very little to help organizations determine whether a risk can be safely ignored, delayed, or otherwise deprioritized.”

His recommendation is that all organizations take a new approach to remediation efficiency by focusing on the remediation of exposures that lie on choke points. Those are the exposures that provide attackers with a fast track to causing significant harm to the organization.

“By identifying and ignoring dead ends to reduce workload,” he told SecurityWeek, “organizations can free up resources to focus on choke points for remediation. Be sure to start with the choke points that indicate a large percentage of critical assets are at risk and continue from there.”

Tel Aviv, Israel-based XM Cyber was founded in 2016 by Boaz Gorodissky, Noam Erez, and Tamir Pardo. It raised a total of $49 million before being acquired by Germany’s Schwarz Group for $700 million in November 2021. The firm operates an attack simulation platform that demonstrates how attackers leverage weaknesses to compromise critical assets in cloud and on-prem environments.

Related: Vulnerabilities Being Exploited Faster Than Ever: Analysis

Related: The History and Evolution of Zero Trust

Related: Tackling the Challenge of Actionable Intelligence Through Context

Related: XM Cyber Unveils Automated Purple-Teaming at Speed and Scale

https://www.securityweek.com/most-attack-paths-are-dead-ends-but-2-lead-to-critical-assets-report/




Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days

Apple on Friday pushed out a major iOS security update to fix a pair of zero-day vulnerabilities already being exploited in the wild.

The newest iOS 16.4.1 and iPadOS 16.4.1 updates cover code execution software flaws in IOSurfaceAccelerator and WebKit, suggesting a complex exploit chain was detected in the wild hitting the latest iPhone devices.

“Apple is aware of a report that this issue may have been actively exploited,” Cupertino says in a barebones advisory that credits Google and Amnesty International with reporting the issue.

The advisory documents two separate issues — CVE-2023-28205 and CVE-2023-28206 — that expose iPhones and iPads to arbitrary code execution attacks.

Apple described the IOSurfaceAccelerator flaw as an out-of-bounds write issue that was addressed with improved input validation.

The WebKit bug, which has already been exploited via web content to execute arbitrary code with kernel privileges, has been fixed with improved memory management.

The company did not say if the newly discovered exploits are capable of bypassing the Lockdown Mode feature that Apple shipped to deter these types of attacks.

The iOS patch comes alongside news from Google that commercial spyware vendors are burning through zero-days to infect mobile devices with surveillance malware.

In one of the two campaigns described by Google this week, an attack started with a link being sent to the targeted user via SMS. When clicked, the link took the victim to malicious websites delivering Android or iOS exploits — depending on the target’s device. Once the exploits were delivered, victims were redirected to legitimate websites, likely in an effort to avoid raising suspicion. 

The iOS exploit chain also hit a WebKit vulnerability (CVE-2022-42856) that Apple patched in iPhones in December 2022. Attacks also involved a Pointer Authentication (PAC) bypass technique, and an exploit for CVE-2021-30900, a sandbox escape and privilege escalation vulnerability that Apple patched in iOS in 2021. 

So far this year, there have been at least 24 documented zero-day vulnerabilities exploited in the wild prior to discovery.

Related: Apple Adds ‘Lockdown Mode’ to Thwart .Gov Mercenary Spyware 

Related: Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors

elated: Can ‘Lockdown Mode’ Solve Apple’s Mercenary Spyware Problem?

https://www.securityweek.com/apple-ships-urgent-ios-patch-for-newly-exploited-zero-days/




Tesla Retail Tool Vulnerability Led to Account Takeover

A vulnerability in the Tesla Retail Tool (TRT) application allowed a researcher to take over the accounts of former employees.

Designed with support for both employee and vendor logins, TRT stores various types of enterprise information, including financial information, details on Tesla locations, contact information, building plans, network circuit details, and details on local, ISP, and utility account logins.

The application allows both internal and external account logins and uses for authentication a JSON Web Token (JWT) that specifies an email address cleared for manually defined user accounts, security researcher Evan Connelly explains.

“At Tesla’s scale, it would be hard to manually update that list every time an employee leaves. And in theory, it should be okay if past employees have access defined within a web app, as their IDP account would be disabled or deleted and thus unable to login to the app through Tesla’s internal IDP,” Connelly notes.

The researcher discovered not only that accounts of past employees were still lurking in Tesla’s internal systems, but also that it was possible to register an external account with the internal email of a former employee, and then access TRT with the privileges of that employee’s account.

After searching online for former Tesla employees who might have had access to TRT, the researcher was able to use their internal Tesla email addresses to register external accounts that allowed him to access the TRT.

Because account privileges were defined by email address, Connelly could log into TRT with the privileges of the disabled accounts, essentially taking over those accounts.

The issue, Connelly explains, was that TRT was created with support for both an internal and an external identity provider, but it did not check which of the providers the user logged in with.

The researcher reported the vulnerability to Tesla on November 19, 2022, through the company’s bug bounty program on Bugcrowd. The flaw was addressed within two days.

It’s unclear how much Connelly earned for his findings, but Tesla assigned the vulnerability a P1 priority rating, for which the carmaker typically pays between $3,000 and $15,000. 

Related:Tesla Hacked Twice at Pwn2Own Exploit Contest

Related:German Consumer Group Sues Tesla Over Privacy, Climate

Related: Researcher Shows How Tesla Key Card Feature Can Be Abused to Steal Cars

https://www.securityweek.com/tesla-retail-tool-vulnerability-led-to-account-takeover/




Sophos Patches Critical Code Execution Vulnerability in Web Security Appliance

Sophos this week announced security updates that resolve several vulnerabilities in Sophos Web Appliance, including a critical bug leading to code execution.

A web security solution, the Sophos Web Appliance allows administrators to set web access policies, define them by users or groups, and enforce them as necessary, from a single interface.

The critical issue, tracked as CVE-2023-1671 (CVSS score of 9.8), was identified in the warning page handler of the appliance and it could be exploited without authentication.

Sophos describes the bug as “a pre-auth command injection vulnerability in the warn-proceed handler allowing execution of arbitrary code”.

The cybersecurity company resolved the flaw with the release of Sophos Web Appliance 4.3.10.4, which addresses two other bugs as well.

The first is a high-severity code execution issue in the exception wizard. Tracked as CVE-2022-4934 (CVSS score of 7.2) and described as a command injection vulnerability, the flaw requires authentication for successful exploitation.

The second is CVE-2020-36692, a medium-severity cross-site scripting (XSS) flaw in the report scheduler. An attacker could exploit the vulnerability to execute JavaScript code in the victim’s browser.

“The victim must be tricked into submitting a malicious form on an attacker-controlled website while logged in to [Sophos Web Appliance] for the attack to succeed,” the cybersecurity firm explains.

Patches for all vulnerabilities are delivered to Sophos Web Appliance users via automatic updates. Sophos recommends placing the appliance behind a firewall and blocking internet access to it.

Sophos Web Appliance is set to reach end-of-life (EoL) status on July 20, 2023. Sophos recommends that Web Appliance customers migrate to Sophos Firewall.

Related: Several Code Execution Vulnerabilities Patched in Sophos Firewall

Related: Sophos Firewall Zero-Day Exploited in Attacks on South Asian Organizations

Related:Sophos Warns of Attacks Exploiting Recent Firewall Vulnerability

https://www.securityweek.com/sophos-patches-critical-code-execution-vulnerability-in-web-security-appliance/




Cisco Patches Code and Command Execution Vulnerabilities in Several Products

Cisco this week announced patches for multiple vulnerabilities across its product portfolio, including high-severity issues impacting its Secure Network Analytics and Identity Services Engine (ISE) products.

Tracked as CVE-2023-20102, the first bug is described as insufficient sanitization of user-provided data parsed into memory. An authenticated, remote attacker could send crafted HTTP requests to an affected device to achieve arbitrary code execution.

Cisco has addressed the vulnerability with the release of Secure Network Analytics 7.4.1-Patch SMC Rollup #5.

The tech giant also announced patches for an improper validation of parameters sent to the restricted shell in Cisco ISE, which could lead to privilege escalation.

An authenticated, local attacker could exploit the issue by sending crafted CLI commands, allowing them to escape the restricted shell and gain root privileges on the operating system. Tracked as CVE-2023-20122, the vulnerability was addressed with the release of ISE version 3.2P1.

Cisco’s advisory also details a second improper validation of parameters flaw that impacts the restricted shell of Evolved Programmable Network Manager (EPNM), ISE, and Prime Infrastructure.

Tracked as CVE-2023-20121, the bug has a severity rating of ‘medium’ because administrator privileges are required for exploitation.

This week, Cisco also announced that a full patch is being released for a critical vulnerability in its Expressway series and TelePresence Video Communication Server (VCS) enterprise collaboration solutions.

Tracked as CVE-2022-20812 (CVSS score of 9.0), the flaw impacts the cluster database API of the affected products and allows an authenticated, remote attacker to overwrite files on the affected device with root privileges, Cisco explains in an advisory.

The issue exists because user-supplied command arguments are not sufficiently validated. To exploit the vulnerability, an attacker needs to authenticate with administrative read-write privileges and submit crafted input.

A partial fix for this vulnerability was included in Expressway series and TelePresence VCS release 14.0.7. A full patch will be included in release 14.3, which is expected to become available in late April.

Cisco also warns of two high-severity vulnerabilities (CVE-2023-20117 and CVE-2023-20128) impacting Small Business RV320 and RV325 routers that could allow an authenticated, remote attacker to execute arbitrary commands on the affected devices.

However, because the affected routers have an end-of-life (EoL) status, Cisco will not release patches to address these vulnerabilities.

No patches will be released for over 15 medium-severity vulnerabilities in EoL Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers either, the tech giant says.

Multiple medium-severity flaws were addressed this week in Cisco Webex Meetings, Unified Contact Center Express (Unified CCX), Secure Network Analytics, Prime Infrastructure and Evolved Programmable Network Manager (EPNM), ISE, Duo Two-Factor Authentication, and Packet Data Network Gateway (PGW).

Cisco says it is not aware of any of these security defects being exploited in attacks. Additional information on these vulnerabilities can be found on Cisco’s product security page.

Related: Cisco Patches High-Severity Vulnerabilities in IOS Software

Related: Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

Related:Cisco Patches Critical Vulnerability in IP Phones

https://www.securityweek.com/cisco-patches-code-and-command-execution-vulnerabilities-in-several-products/