개요
Cisco 제품에서 발생하는 여러 취약점을 해결하는 보안 업데이트가 발표되었다. 대상은 Cisco RoomOS, Cisco Catalyst Center, Cisco Catalyst Center Global Manager, Secure Endpoint Connector for Linux/Mac/Windows이다.
주요 취약점
- Cisco RoomOS의 CVE-2026-20150은 부적절한 접근 통제 취약점이다.
- Cisco RoomOS의 CVE-2026-20153은 부적절한 입력값 검증 취약점이다.
- Cisco RoomOS의 CVE-2026-20156은 메모리 버퍼 경계 내 작업 제한 미흡 취약점이다.
- Cisco RoomOS의 CVE-2026-20157은 암호화 미적용 취약점이다.
- Cisco RoomOS의 CVE-2026-20158은 리소스 수명주기 관리 미흡 취약점이다.
- Cisco RoomOS의 CVE-2026-20187은 예외 상황 처리 미흡 취약점이다.
- Cisco Catalyst Center의 CVE-2026-20191은 임의 파일 읽기 취약점이다.
- ClamAV 관련 CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244는 메모리 손상 또는 정수 오버플로우 등으로 인한 서비스 거부 취약점이다.
영향 대상과 업데이트 버전
- Cisco RoomOS는 On-Premises Operation에서 11.32.6.0 이상, 26.5.2.2 이상이 필요하다.
- Cisco RoomOS는 Cloud-Aware Operation에서 11.39.1.1 이상, RoomOS June 2026(26.7.1.7) 이상이 필요하다.
- Cisco Catalyst Center Hardware Appliances와 AWS, Azure Virtual Appliances는 3.1.6 GSMU200 이상이 필요하다.
- Cisco Catalyst Center Virtual Appliances on VMware ESXi는 2.3.7.11-VA GSMU100 이상 또는 3.1.6 GSMU200 이상이 필요하다.
- Cisco Catalyst Center Global Manager는 Cisco CCGM 1.4.1 이상이 필요하다.
- Secure Endpoint Connector for Linux는 1.29.0 이상, Mac은 1.27.2 이상, Windows는 8.6.2 이상이 필요하다.
참고
공개된 참고사이트는 Cisco RoomOS Security Hardening Release: July 2026, Cisco Catalyst Center Arbitrary File Read Vulnerability, ClamAV Vulnerabilities Affecting Cisco Products: July 2026이다.