Cisco Fixes 12 Security Flaws in SD-WAN and IOS XE Software, Three Rated Critical
Cisco has issued security updates addressing 12 vulnerabilities found in its Catalyst SD-WAN Software and IOS XE Software, discovered during an internal security review. Three of these flaws received the highest possible severity rating of 9.8 out of 10 on the CVSS scale, indicating they could be exploited relatively easily and with serious consequences if left unpatched.
The vulnerabilities affect Cisco Catalyst SD-WAN Software regardless of how devices are configured, and IOS XE Software when running in autonomous or controller mode. Cisco networking equipment is widely used by organisations of all sizes, including many Australian small and medium businesses that rely on it for internet connectivity, routing, and network security.
While Cisco has not indicated that these vulnerabilities are currently being exploited in the wild, unpatched network infrastructure is a common entry point for attackers. Businesses using Cisco SD-WAN or IOS XE devices should check with their IT provider or managed service provider to confirm whether their equipment is affected and apply the available updates as soon as possible.