Security Alerts

  • Home
  • Security Alerts

Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

VMware has released security updates to address three vulnerabilities in Aria Operations for Networks. The most critical flaw is a command injection vulnerability that could allow remote code execution by an attacker with network access. Another vulnerability involves deserialization attacks that could result in remote code execution. Additionally, there is a high-severity information disclosure bug that could lead to command injection and access to sensitive data. The vulnerabilities affect VMware Aria Operations Networks version 6.x, and the recommended solution is to update to the patched versions. In a separate development, Cisco has fixed a critical privilege escalation flaw in its Expressway Series and TelePresence Video Communication Server (VCS), which could allow an attacker to elevate privileges and alter passwords. Cisco has provided workarounds and updated versions to address these issues. While there is no evidence of active exploitation, it is crucial to apply patches promptly to mitigate risks. Furthermore, three security vulnerabilities have been discovered in RenderDoc, an open-source graphics debugger, which could allow attackers to gain elevated privileges and execute arbitrary code.

Link

https://thehackernews.com/2023/06/urgent-security-updates-cisco-and.html