Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Cisco fixes critical pre-auth flaws allowing router takeover
#1
Quote:Cisco today has released security updates to address critical remote code execution (RCE), authentication bypass, and static default credential vulnerabilities affecting multiple router and firewall devices that could lead to full device takeover.

Cisco also issued a security update to patch a privilege escalation vulnerability in the Cisco Prime License Manager software.

According to the company, there are no workarounds that could be applied to address these vulnerabilities.

The five security flaws patched today received 9.8 CVSS base score qualitative severity ratings from Cisco which makes them all critical vulnerabilities.

Remotely exploitable by unauthenticated attackers

They can also be remotely exploited by unauthenticated attackers as part of low complexity attacks that don't require user interaction.

A full list of all critical security issues addressed by Cisco today is available in the table embedded below, together with links to their respective security advisories.

Continue reading HERE
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  700,000 WordPress Sites Vulnerable to Takeover, No Fix Available mrtrout 0 104 11-12-2024 , 11:32 PM
Last Post: mrtrout
  Atlassian reveals critical flaws in almost everything it makes and touches mrtrout 0 751 07-21-2022 , 07:56 PM
Last Post: mrtrout
  Microsoft November 2021 Patch Tuesday fixes 6 zero-days, 55 flaws mrtrout 0 689 11-09-2021 , 10:20 PM
Last Post: mrtrout
  F5 urges customers to patch 4 critical BIG-IP pre-auth RCE bugs Bjyda 0 1,073 03-11-2021 , 10:48 PM
Last Post: Bjyda
  Multiple Cisco products exposed to DoS attack due to a Snort issue Bjyda 0 1,279 03-07-2021 , 11:01 PM
Last Post: Bjyda



Users browsing this thread: 1 Guest(s)