可以利用思科openVuln API,自动化的查询特定思科产品的安全漏洞,并且通过Excel的方式展现这些漏洞信息,也可以通过思科提供的图形化界面来查询漏洞信息,可以登录网站https://sec.cloudapps.cisco.com/security/center/publicationListing.x查询思科设备的漏洞信息。也可以查询特定版本的漏洞信息,链接:https://sec.cloudapps.cisco.com/security/center/softwarechecker.x
请参考如下Security advisories
...
At the time of publication, CVE-2023-20028 affected the following Cisco products:
At the time of publication, CVE-2023-20119 affected Cisco Secure Email and Web Manager, both virtual and hardware appliances.
At the time of publication, CVE-2023-20120 affected the following Cisco products:
For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.
Only products listed in the Vulnerable Products section of this advisory are known to be affected by this vulnerability.
Cisco has confirmed that CVE-2023-20028 does not affect Cisco Secure Email Gateway, both virtual and hardware appliances.
Cisco has confirmed that CVE-2023-20119 does not affect the following Cisco products:
...
There are no workarounds that address these vulnerabilities.
At the time of publication, the release information in the following tables was accurate. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.
The left column lists Cisco software releases, and the right column indicates whether a release was affected by the vulnerabilities that are described in this advisory and which release included the fix for these vulnerabilities.
Secure Email and Web Manager
Cisco AsyncOS Release | First Fixed Release for CVE-2023-20028, CVE-2023-20119, and CVE-2023-20120 |
---|---|
14.3 and earlier | Migrate to a fixed release. |
15.0 | 15.0.01 (Jul 2023) |
Secure Email Gateway
Cisco AsyncOS Release | First Fixed Release for CVE-2023-20120 |
---|---|
14.3 and earlier2 | Migrate to a fixed release. |
15.0 | 15.0.01 (Jul 2023) |
Secure Web Appliance
Cisco AsyncOS Release | First Fixed Release for CVE-2023-20028 and CVE-2023-20120 |
---|---|
14.5 and earlier | Migrate to a fixed release. |
15.0 | 15.0.0-3321 |
In most cases, the software can be upgraded over the network by using the System Upgrade options in the web interface of the appliance. To upgrade a device by using the web interface, do the following:
After the upgrade is complete, the device reboots.
The Cisco Product Security Incident Response Team (PSIRT) validates only the affected and fixed release information that is documented in this advisory.
...