11 High-Severity Flaws in Security Products Patched by Cisco

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

 

This week, Cisco released its April 2022 bundle of security advisories for Cisco Adaptive Security Appliance (ASA), Firepower Threat Defense (FTD), and Firepower Management Center (FMC). 
The semiannual bundled advisories include a total of 19 flaws in Cisco security products, with 11 of them being classified as “high severity.” 
CVE-2022-20746 (CVSS score of 8.8) is the most serious of these, an FTD security vulnerability that occurs because TCP flows aren’t appropriately handled and might be exploited remotely without authentication to generate a denial of service (DoS) condition. 
“An attacker could exploit this vulnerability by sending a crafted stream of TCP traffic through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition,” Cisco explains in an advisory. 
With the introduction of FDT versions 6.6.5.2 and 7.1.0.1, the IT giant has addressed the problem. Fixes will also be included in FDT releases 6.4.0.15 and 7.0.2, which will be released next month. Several more DoS vulnerabilities, all rated “high severity,” were fixed with the same FDT releases, including ones that affect ASA as well. They were addressed in ASA releases 9.12.4.38, 9.14.4, 9.15.1.21, 9.16.2.14, and 9.17.1.7

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: