{"id":104003,"date":"2022-04-22T05:25:04","date_gmt":"2022-04-22T07:25:04","guid":{"rendered":"https:\/\/teknomers.com\/fr\/cisco-publie-des-correctifs-de-securite-pour-telepresence-roomos-et-umbrella-va\/"},"modified":"2022-04-22T05:25:09","modified_gmt":"2022-04-22T07:25:09","slug":"cisco-publie-des-correctifs-de-securite-pour-telepresence-roomos-et-umbrella-va","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/cisco-publie-des-correctifs-de-securite-pour-telepresence-roomos-et-umbrella-va\/","title":{"rendered":"Cisco publie des correctifs de s\u00e9curit\u00e9 pour TelePresence, RoomOS et Umbrella VA"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Le fabricant d&#8217;\u00e9quipements de r\u00e9seau Cisco a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour r\u00e9soudre trois vuln\u00e9rabilit\u00e9s de haute gravit\u00e9 dans ses produits qui pourraient \u00eatre exploit\u00e9es pour provoquer une condition de d\u00e9ni de service (DoS) et prendre le contr\u00f4le des syst\u00e8mes concern\u00e9s.<\/p>\n<p>Le premier des trois d\u00e9fauts, <strong>CVE-2022-20783<\/strong> (score CVSS\u00a0: 7,5), affecte le logiciel Cisco TelePresence Collaboration Endpoint (CE) et le logiciel Cisco RoomOS, et d\u00e9coule d&#8217;un manque de validation d&#8217;entr\u00e9e appropri\u00e9e, permettant \u00e0 un attaquant distant non authentifi\u00e9 d&#8217;envoyer un trafic sp\u00e9cialement con\u00e7u aux appareils.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset1\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Nouveau-Wiper-Malware-ciblant-lUkraine-dans-le-cadre-de-loperation.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>&#8220;Un exploit r\u00e9ussi pourrait permettre \u00e0 l&#8217;attaquant de faire red\u00e9marrer l&#8217;appareil concern\u00e9 soit normalement, soit en mode maintenance, ce qui pourrait entra\u00eener une condition DoS sur l&#8217;appareil&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ce-roomos-dos-c65x2Qf2\" target=\"_blank\">c&#8217;est not\u00e9<\/a> dans un avis.<\/p>\n<p>La National Security Agency (NSA) des \u00c9tats-Unis est cr\u00e9dit\u00e9e d&#8217;avoir d\u00e9couvert et signal\u00e9 la faille.  Le probl\u00e8me a \u00e9t\u00e9 r\u00e9solu dans les versions 9.15.10.8 et 10.11.2.2 du logiciel Cisco TelePresence CE.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-uva-static-key-6RQTRs4c\" target=\"_blank\"><strong>CVE-2022-20773<\/strong><\/a>  (score CVSS\u00a0: 7,5), la deuxi\u00e8me faille \u00e0 corriger concerne une cl\u00e9 d&#8217;h\u00f4te SSH statique pr\u00e9sente dans Cisco Umbrella Virtual Appliance (VA) ex\u00e9cutant une version logicielle ant\u00e9rieure \u00e0 la 3.3.2, permettant potentiellement \u00e0 un attaquant d&#8217;effectuer un man-in -the-middle (MitM) attaque une connexion SSH et d\u00e9tourne les informations d&#8217;identification de l&#8217;administrateur.<\/p>\n<p>Une troisi\u00e8me vuln\u00e9rabilit\u00e9 tr\u00e8s grave est un cas d&#8217;\u00e9l\u00e9vation de privil\u00e8ges dans Cisco Virtualized Infrastructure Manager (<strong>CVE-2022-20732<\/strong>, score CVSS : 7,8) qui permet \u00e0 un attaquant local authentifi\u00e9 d&#8217;\u00e9lever les privil\u00e8ges sur les appareils.  Il a \u00e9t\u00e9 r\u00e9solu dans la version 4.2.2 du logiciel.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>&#8220;Un exploit r\u00e9ussi pourrait permettre \u00e0 l&#8217;attaquant d&#8217;obtenir des informations d&#8217;identification de base de donn\u00e9es internes, que l&#8217;attaquant pourrait utiliser pour afficher et modifier le contenu de la base de donn\u00e9es. L&#8217;attaquant pourrait utiliser cet acc\u00e8s \u00e0 la base de donn\u00e9es pour \u00e9lever les privil\u00e8ges sur l&#8217;appareil affect\u00e9&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9. <a rel=\"nofollow noopener\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-vim-privesc-T2tsFUf\" target=\"_blank\">mentionn\u00e9<\/a>.<\/p>\n<p>Cisco s&#8217;int\u00e9resse \u00e9galement aux <a rel=\"nofollow noopener\" href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\" target=\"_blank\">10 bogues de gravit\u00e9 moyenne<\/a> couvrant son portefeuille de produits, y compris Webex Meeting, les produits de communications unifi\u00e9es, Umbrella Secure Web Gateway et le logiciel IOS XR.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/cisco-releases-security-patches-for.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le fabricant d&#8217;\u00e9quipements de r\u00e9seau Cisco a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour r\u00e9soudre trois vuln\u00e9rabilit\u00e9s de haute gravit\u00e9 dans ses produits qui pourraient \u00eatre exploit\u00e9es pour provoquer une condition de d\u00e9ni de service (DoS) et prendre le contr\u00f4le des syst\u00e8mes concern\u00e9s. Le premier des trois d\u00e9fauts, CVE-2022-20783 (score CVSS\u00a0: 7,5), affecte le [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":104004,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[5859,4168,15954,4158,4165,4161,133,4157,4159,4171,4170,4167,4160,4163,4162,185,2212,53855,1835,4172,4169,15957,44254,4166,4164],"class_list":["post-104003","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-cisco","tag-comment-pirater","tag-correctifs","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-publie","tag-roomos","tag-securite","tag-securite-informatique","tag-securite-internet","tag-telepresence","tag-umbrella","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/104003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=104003"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/104003\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/104004"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=104003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=104003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=104003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}