02-14-2023 09:55 AM - last edited on 06-02-2023 02:39 PM by Tyler Langston
I have been told that there is a security vulnerability on IOSXE 17.9.2 code to run ThousandEyes agent on Catalyst 9300/9400. And the vulnerability is CSCwd25783. But I could not find this vulnerability in cisco websites.
Can anyone help me clarify about this vulnerability.
02-14-2023 10:58 AM
as per i know anything above 17.3.X should work as expected, I have tested 17.3.3 and 17.3.6 as expected working (some proxy issue around I am digging more debugs to fix that) if no proxy involved all good here. There are some additional docker options required I still did not find information, on how the app can use Local NTP and Local DNS in a corporate environment if you use Public DNS and public NTP works as expected.
what is your issue here ? installation or security issue only concerned?
02-14-2023 10:57 PM
Hi Balaji,
Thank You for the response
My concern is that we have been told that there an App-hosting security issues identified
Cisco has not yet announced any information as there’s no fixed release version yet (just SMU patch on top of 17.9.2).
The major vulnerabilities has been fixed by the Cisco with the patched SMU(snapshot below) which we have to install post upgrading the IOS.
What is this vulnerability. I cannot find it anywhere in Cisco websites..
02-15-2023 02:52 PM
thank you, not that i am aware, contact TAC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide