[subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Cisco has released patches to address a maximum-severity security flaw in Smart Software Manager On-Prem (Cisco SSM On-Prem) that could allow a remote, unauthenticated attacker to change the passwords of any users, including administrative users. The vulnerability list is provided below.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Cisco has released patches to address a maximum-severity security flaw in Smart Software Manager On-Prem (Cisco SSM On-Prem) that could allow a remote, unauthenticated attacker to change the passwords of any users, including administrative users. The vulnerability list is provided below.[emaillocker id="1283"]
- CVE-2024-20419: Cisco Smart Software Manager On-Prem (SSM On-Prem). This flaw allows remote, unauthenticated attackers to change any user’s password, including administrative users, by sending crafted HTTP requests. It impacts versions 8-202206 and earlier, fixed in version 8-202212. No workarounds are available, and no malicious exploitation has been reported.
- CVE-2024-20401: Cisco Secure Email Gateway (SEG). This vulnerability allows attackers to add new users with root privileges and crash appliances using emails with malicious attachments. It impacts devices running vulnerable releases of Cisco AsyncOS with specific features enabled. A patch is available via Content Scanner Tools package versions 23.3.0.4823 and later.
- CVE-2024-34102: Adobe Commerce and Magento Open Source XXE Vulnerability.
- CVE-2024-28995: SolarWinds Serv-U Path Traversal Vulnerability.
- CVE-2022-22948: VMware vCenter Server Incorrect Default File Permissions Vulnerability.
RECOMMENDATION:
We strongly recommend you update below version and updates for product.
CVE-2024-20419:
| Cisco SSM On-Prem Release |
First Fixed Release |
| 8-202206 and earlier |
8-202212 |
| 9 |
Not vulnerable |
CVE-2024-20401:
- The fix for this vulnerability is distributed through an updated version of the Content Scanner Tools package. Content Scanner Tools versions 23.3.0.4823 and later contain the fix for this vulnerability.
- The updated version of Content Scanner Tools is included by default in Cisco AsyncOS for Cisco Secure Email Software releases 15.5.1-055 and later.
Manual Update:
- To manually update the Content Scanner Tools, use the command CLI contentscannerupdate, as shown in the following example:
- cisco-esa> contentscannerupdate
CVE-2022-22948:
- Upgrade vCenter Server: To version 7.0 U3d or later.
- Upgrade Cloud Foundation: To version 4.4.1 or later.
Also, search for your product version and download it.
Download here: https://www.cisco.com/c/en/us/support/index.html
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/07/cisco-warns-of-critical-flaw-affecting.html
[/emaillocker]