Cisco Releases Security Updates
Cisco has released updates to address vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.
NCCIC/US-CERT encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates:
- Cisco IOS XE Software Static Credential Vulnerability cisco-sa-20180328-xesc
- Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability cisco-sa-20180328-smi2
- Cisco IOS and IOS XE Software Quality of Service Remote Code Execution Vulnerability cisco-sa-20180328-qos
- Cisco IOS XE Software Web UI Remote Access Privilege Escalation Vulnerability cisco-sa-20180328-xepriv
- Cisco IOS XE Software Simple Network Management Protocol Double-Free Denial of Service Vulnerability cisco-sa-20180328-snmp-dos
- Cisco IOS Software Simple Network Management Protocol GET MIB Object ID Denial of Service Vulnerability cisco-sa-20180328-snmp
- Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability cisco-sa-20180328-smi
- Cisco IOS XE Software User EXEC Mode Root Shell Access Vulnerabilities cisco-sa-20180328-privesc1
- Cisco IOS XE Software with Cisco Umbrella Integration Denial of Service Vulnerability cisco-sa-20180328-opendns-dos
- Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities cisco-sa-20180328-lldp
- Cisco IOS XE Software for Cisco Catalyst Switches IPv4 Denial of Service Vulnerability cisco-sa-20180328-ipv4
- Cisco IOS and IOS XE Software Internet Key Exchange Version 1 Denial of Service Vulnerability cisco-sa-20180328-ike-dos
- Cisco IOS and IOS XE Software Internet Key Exchange Memory Leak Vulnerability cisco-sa-20180328-ike
- Cisco IOS XE Software Internet Group Management Protocol Memory Leak Vulnerability cisco-sa-20180328-igmp
- Cisco IOS XE Software Zone-Based Firewall IP Fragmentation Denial of Service Vulnerability cisco-sa-20180328-fwip
- Cisco IOS Software Integrated Services Module for VPN Denial of Service Vulnerability cisco-sa-20180328-dos
- Cisco IOS and IOS XE Software DHCP Version 4 Relay Denial of Service Vulnerability cisco-sa-20180328-dhcpr3
- Cisco IOS and IOS XE Software DHCP Version 4 Relay Reply Denial of Service Vulnerability cisco-sa-20180328-dhcpr2
- Cisco IOS and IOS XE Software DHCP Version 4 Relay Heap Overflow Denial of Service Vulnerability cisco-sa-20180328-dhcpr1
- Cisco IOS and IOS XE Software Bidirectional Forwarding Detection Denial of Service Vulnerability cisco-sa-20180328-bfd
This product is provided subject to this Notification and this Privacy & Use policy.