Cisco Warns of Unpatched Email Flaws, Patches Critical Switch Vulnerabilities
Cisco Systems has issued warnings about two unpatched vulnerabilities in its enterprise email security product Secure Email, as well as multiple critical-severity security defects in IOS XR and Nexus 9000 series switches.
The company said that insufficient validation of message integrity can allow an attacker to intercept and modify traffic between email gateways using a man-in-the-middle (MitM) technique. This could enable the attacker to obtain plaintext content from encrypted communication, affecting all Secure Email devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled.
Cisco noted that it is not aware of any exploitation of these vulnerabilities in the wild and emphasized that they have been publicly disclosed. The company also released patches for multiple critical-severity security defects in IOS XR, including memory corruption and memory safety bugs, as well as improper access control issues. Additionally, Nexus 9000 series switches received fixes for a vulnerability that allows remote attackers to connect to by-default accessible TCP ports and execute code with root privileges.