보안 권고문

Cisco 제품 보안 업데이트 권고

개요


Cisco 제품에서 발생하는 여러 취약점을 해결하는 보안 업데이트가 발표되었다. 대상은 Cisco RoomOS, Cisco Catalyst Center, Cisco Catalyst Center Global Manager, Secure Endpoint Connector for Linux/Mac/Windows이다.

주요 취약점


  • Cisco RoomOS의 CVE-2026-20150은 부적절한 접근 통제 취약점이다.
  • Cisco RoomOS의 CVE-2026-20153은 부적절한 입력값 검증 취약점이다.
  • Cisco RoomOS의 CVE-2026-20156은 메모리 버퍼 경계 내 작업 제한 미흡 취약점이다.
  • Cisco RoomOS의 CVE-2026-20157은 암호화 미적용 취약점이다.
  • Cisco RoomOS의 CVE-2026-20158은 리소스 수명주기 관리 미흡 취약점이다.
  • Cisco RoomOS의 CVE-2026-20187은 예외 상황 처리 미흡 취약점이다.
  • Cisco Catalyst Center의 CVE-2026-20191은 임의 파일 읽기 취약점이다.
  • ClamAV 관련 CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244는 메모리 손상 또는 정수 오버플로우 등으로 인한 서비스 거부 취약점이다.

영향 대상과 업데이트 버전


  • Cisco RoomOS는 On-Premises Operation에서 11.32.6.0 이상, 26.5.2.2 이상이 필요하다.
  • Cisco RoomOS는 Cloud-Aware Operation에서 11.39.1.1 이상, RoomOS June 2026(26.7.1.7) 이상이 필요하다.
  • Cisco Catalyst Center Hardware Appliances와 AWS, Azure Virtual Appliances는 3.1.6 GSMU200 이상이 필요하다.
  • Cisco Catalyst Center Virtual Appliances on VMware ESXi는 2.3.7.11-VA GSMU100 이상 또는 3.1.6 GSMU200 이상이 필요하다.
  • Cisco Catalyst Center Global Manager는 Cisco CCGM 1.4.1 이상이 필요하다.
  • Secure Endpoint Connector for Linux는 1.29.0 이상, Mac은 1.27.2 이상, Windows는 8.6.2 이상이 필요하다.

참고


공개된 참고사이트는 Cisco RoomOS Security Hardening Release: July 2026, Cisco Catalyst Center Arbitrary File Read Vulnerability, ClamAV Vulnerabilities Affecting Cisco Products: July 2026이다.