The Exploit

Notes from the Front Lines of Penetration Testing

Cisco Patches Critical Security Vulnerabilities

Cisco Patches Critical Security Vulnerabilities
Affected Products

The critical and high-severity vulnerabilities that were patched affect many products across Cisco’s product line including:

  • Cisco SD-WAN
  • Cisco DNA Center Command Runner
  • Cisco DNA Center
  • Cisco Smart Software Manager Satellite Web UI
  • Cisco Data Center Network Manager
  • Cisco Finesse OpenSocial Gadget Editor
  • Cisco Secure Web Appliance
  • Cisco Advanced Malware Protection for Endpoints and Immunet for Windows
  • Cisco Umbrella Dashboard

For a complete list of affected products, check Cisco’s Security Center.

The Vulnerabilities Addressed

The patches addressed numerous critical vulnerabilities and exposures (CVEs), including serious threats such as command injections, SQL injections, DLL hijacking, cross-site request forgery attacks, directory traversals, and more. Some of the most critical, such as a buffer overflow in SD-Wan, allow for unauthenticated, remote code execution as the root user and should be patched immediately. Cisco does not believe these were actively being used in the wild, but they should nonetheless be treated seriously and patched immediately. 

Remediation

Cisco recommends patching all affected products as soon as possible as there are no current workarounds to the newly released critical vulnerabilities. A full list of Cisco’s recent security advisories is also available from the company’s security center.

Does your company have a vulnerability management plan in place? Take a look at this video as Raxis’ CTO Brian Tant explains why you should.


Raxis Administrator

Posted on

Categories: ,

Also by Raxis Administrator

Human Vs AI Pentesting

While AI tools offer speed in detecting known vulnerabilities, they fall short with 20-35% false positives and only 50-65% success on complex threats like business logic flaws, as per mainstream reports from Verizon and OWASP. Human penetration testers at Raxis deliver 85-90% detection rates, precise prioritization, and ethical adaptability, ensuring your organization stays ahead of real-world attacks.

Partner With Raxis

Partnering with Raxis empowers your business with elite penetration testing services, competitive reseller pricing, and recurring revenue opportunities, all backed by a proven track record of excellence and a commitment to staying ahead of evolving cybersecurity threats.

Penetration Testing

Tailored, expert-led penetration testing services that uncovers hidden vulnerabilities using real-world hacker techniques, providing actionable insights to strengthen your defenses and protect against sophisticated cyber threats.

Ready to See Raxis One In Action?

See how we transform traditional pen testing into interactive security intelligence that keeps you informed every step of the way. From real-time attack progression to detailed remediation guidance, Raxis One gives you unprecedented visibility into your security posture as it’s being tested.