Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Cisco fixes critical pre-auth flaws allowing router takeover
#1
Quote:Cisco today has released security updates to address critical remote code execution (RCE), authentication bypass, and static default credential vulnerabilities affecting multiple router and firewall devices that could lead to full device takeover.

Cisco also issued a security update to patch a privilege escalation vulnerability in the Cisco Prime License Manager software.

According to the company, there are no workarounds that could be applied to address these vulnerabilities.

The five security flaws patched today received 9.8 CVSS base score qualitative severity ratings from Cisco which makes them all critical vulnerabilities.

Remotely exploitable by unauthenticated attackers

They can also be remotely exploited by unauthenticated attackers as part of low complexity attacks that don't require user interaction.

A full list of all critical security issues addressed by Cisco today is available in the table embedded below, together with links to their respective security advisories.

Continue reading HERE
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Atlassian reveals critical flaws in almost everything it makes and touches mrtrout 0 604 07-21-2022 , 07:56 PM
Last Post: mrtrout
  Microsoft November 2021 Patch Tuesday fixes 6 zero-days, 55 flaws mrtrout 0 545 11-09-2021 , 10:20 PM
Last Post: mrtrout
  F5 urges customers to patch 4 critical BIG-IP pre-auth RCE bugs Bjyda 0 911 03-11-2021 , 10:48 PM
Last Post: Bjyda
  Multiple Cisco products exposed to DoS attack due to a Snort issue Bjyda 0 1,005 03-07-2021 , 11:01 PM
Last Post: Bjyda
  Cisco points to new tier of APT actors that behave more like cybercriminals Bjyda 0 848 02-23-2021 , 11:22 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)