SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Cisco Releases Security Updates for Multiple Products

Cisco Releases Security Updates for Multiple Products

Cisco has released security updates for multiple products to address critical, high, and medium severity vulnerabilities for twelve different Cisco products. Advisories released for Cisco Policy Suite and Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) are...

Nov 8, 2021By Vijay Chachadi3 min read

Cisco has released security updates for multiple products to address critical, high, and medium severity vulnerabilities for twelve different Cisco products. Advisories released for Cisco Policy Suite and Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) are critical. On exploitation, some of these vulnerabilities allow unauthenticated, remote code execution with root privileges. Vulnerability Management System can resolve this issue.

Cisco has released security updates for the following products:

  • Cisco Policy Suite
  • Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT)
  • Cisco Small Business Series Switches
  • Cisco Email Security Appliance
  • Cisco Webex Meetings
  • Cisco Webex Video Mesh
  • Cisco Umbrella
  • Cisco Small Business RV Series Routers
  • Cisco Prime Infrastructure and Evolved Programmable Network Manager
  • Cisco Unified Communications Products
  • Cisco Prime Access Registrar
  • Cisco AnyConnect Secure Mobility Client for Windows

Critical Severity Vulnerabilities

  • CVE-2021-40119: The flaw affects the key-based SSH authentication mechanism of Cisco Policy Suite.  The issue is due to the weakness in the SSH subsystem of an affected system. The affected device can exploit the bug through SSH. A successful exploit could allowthe attacker tolog in to an affected system as the root user.
  • CVE-2021-34795, CVE-2021-40112, CVE-2021-40113: Three vulnerabilities have been reported in the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT). On successful exploitation, these vulnerabilities could allow an unauthenticated, remote attacker to perform actions like login with a default credential if the Telnet protocol is enabled, performing command injection, and hence modifying the configuration.

Both these vulnerabilities are patched by Cisco security update.

High Severity Vulnerabilities

  • CVE-2021-34739: The vulnerability is found to be in the web-based management interface of multiple Cisco Small Business Series Switches. The issue is due to the insufficient expiration of session credentials. On successful exploitation, this vulnerability allows an unauthenticated, remote attacker to replay valid user session credentials and therefore gain unauthorized access to the web-based management interface of an affected device.
  • CVE-2021-34741: A denial of service vulnerability present in the email scanning algorithm of Cisco AsyncOS Software for Cisco Email Security Appliance. The issue is due to insufficient input validation of incoming emails.An attacker can exploit the bug by sending a specially crafted email through Cisco ESA. A successful exploit could lead to denial of service (DoS).

Cisco Security Update finally patches these vulnerabilities.

Medium Severity Vulnerabilities

Cisco has released security updates for all these vulnerabilities. Cisco’s fixes included 12 medium severity vulnerabilities:

CVE-2021-40128, CVE-2021-1500, CVE-2021-40115, CVE-2021-40126, CVE-2021-34773, CVE-2021-40127, CVE-2021-40120, CVE-2021-34784, CVE-2021-34701, CVE-2021-34774, CVE-2021-34731 and  CVE-2021-40124.

Impact

An attacker can exploit these vulnerabilities to execute arbitrary codes and commands with root privileges, privilege escalation, denial of services, and hence the directory traversal attacks on the vulnerable systems.

Solution

We recommend installing the necessary Cisco security updates in November 2021 as soon as possible to stay protected.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026