SELECTED BY THE TALOS SECURITY INTELLIGENCE AND RESEARCH GROUP
Title: Cisco patches high-severity vulnerabilities in some routers
Description: Cisco disclosed five vulnerabilities in its SD-WAN software, three of which are considered high severity. The security flaws leave several products open to exploitation, including some routers and network management systems. CVE-2020-3266 is the most severe of all with a CVSS score of 7.8. A local attacker could exploit the CLI utility in SD-WAN to inject arbittrary commands with root privileges. The company says there are no workarounds as of the release of these exploits, so users are encouraged to patch as soon as possible.
Reference: https://www.networkworld.com/article/3533550/cisco-warns-of-five-sd-wan-security-weaknesses.html
Snort SIDs: 53481 - 53483
Title: Intel Raid Web Console 3 denial-of-service bugs
Description: The Intel RAID Web Console 3's web API contains two denial-of-service vulnerabilities. The Raid Web Console is a web-based application that provides several configuration functions for the Intel RAID line of products, which includes controllers and storage expanders. The console monitors, maintains and troubleshoots these products. An attacker could exploit both these bugs by sending a malicious POST request to the API.
Reference: https://blog.talosintelligence.com/2020/03/vulnerability-spotlight-intel-raid-web-march-2020.html
Snort SIDs: 51652, 51684