Cisco Critical Advisories for September Includes Patch for Struts Vulnerability

Satnam Narang

Cisco has released advisories for 29 issues, including three critical vulnerabilities. The update also includes a patch for CVE-2018-11776 in Apache Struts.

Background

On Wednesday, September 5, Cisco released security advisories for 29 issues, rating three of them as critical. One of these critical vulnerabilities is the Apache Struts vulnerability (CVE-2018-11776) that we wrote about last month. The other two critical vulnerabilities affect Cisco’s Umbrella API (CVE-2018-0435) and several Cisco wireless VPN devices (CVE-2018-0423).

Vulnerability details

While exploitation of the Struts vulnerability is the same as reported in our previous blog, this advisory indicates that the Cisco Identity Services Engine (ISE) is affected.

The Cisco Umbrella API vulnerability, when exploited, could allow an authenticated remote attacker to read and modify data. This vulnerability has already been patched by Cisco and no user action is required.

By exploiting the third critical vulnerability in Cisco wireless VPN devices, a remote attacker sending malicious requests to vulnerable devices can trigger a buffer overflow, which could lead to a Denial of Service (DoS) or execution of arbitrary code. In order to exploit this vulnerability, both the remote management interface and Guest account features must be enabled. However, both of these features are disabled by default.

Urgently required actions

For Cisco ISE users, the related bug and patch information can be found here.

For users with affected Cisco wireless VPN devices, we recommend users update to the latest version of the firmware for the devices, which can be found in Cisco’s software center.

Identifying affected systems

Tenable has released the following plugins related to these advisories.

Plugin ID

Description

112219

Cisco Identity Services Engine Struts2 Namespace Vulnerability


Get more information

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

Read more >

Published on Sep 5, 2018

People also viewed

Channel Sales Engineer

Santiago Santiago Chile Santiago, Chile Sales Engineering Sales
Your Role:The Channel Sales Engineer will support and will be working with production, engineering, and research and development, as well as external sales firms to determine how Tenable products and services could be designed or modified to best ...

Engineering Manager - UI

Los Angeles California United States West Jefferson Boulevard, Playa Vista, Los Angeles, California, United States, 90066 Cloud Platforms Research & Development
Your Role:Tenable is looking for an experienced UI Engineering manager, who would be responsible for leading a team of world class engineers.  This person would be expected to help grow and mentor experience engineers. Background in working with m...

Engineering Manager - UI

San Jose California United States E Santa Clara St., San Jose, California, United States, 95113 Cloud Platforms Research & Development
Your Role:Tenable is looking for an experienced UI Engineering manager, who would be responsible for leading a team of world class engineers.  This person would be expected to help grow and mentor experience engineers. Background in working with m...

Engineering Manager - UI

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 20146 Cloud Platforms Research & Development
Your Role:Tenable is looking for an experienced UI Engineering manager, who would be responsible for leading a team of world class engineers.  This person would be expected to help grow and mentor experience engineers. Background in working with m...

Commercial Territory Manager

Columbia Maryland United States Columbia Gateway Drive, Columbia, Maryland, United States, 20146 Sales Sales
Your Role:The Commercial Territory Manager will meet and exceed quarterly sales quota by developing new opportunities within specific geographical territory.  Researching and identifying potential accounts; outbound cold calling to soliciting new ...

Recruiter - UK

Uxbridge United Kingdom Furzeground Way , Stockley Park, Uxbridge, United Kingdom, UB11 1EZ Human Resources Human Resources
Your Role:Tenable is seeking a talented Recruiter who will source, screen and ultimately close exceptional sales, marketing and professional services talent. You’ll partner with Tenable’s Sales leadership to create and maintain a talent pipeline, ...

We have big plans for continued global growth, and we’re looking for people who are creative, flexible and dedicated to helping us build something great – something that matters.