Saturday, April 1, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Cisco patches multiple products – potential backdoor vulnerability

Kiratas by Kiratas
February 3, 2023
in World
Reading Time: 2 mins read
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Cisco has found and patched vulnerabilities in several products. A total of six products are affected. In Cisco’s IOx Application Hosting Environment, one leak has a high risk rating and the others pose a medium threat.

Cisco: Affected Products

The vulnerability in Cisco’s IOx Application Hosting Environment could allow authenticated attackers from the network to execute arbitrary commands as root in the underlying operating system. The error is due to insufficient filtering of parameters when activating an application. Malicious actors could abuse this by distributing and activating an application with manipulated activation data (CVE-2023-20076, CVSS 7.2Risk “hoch“).

In the security advisory, Cisco mentions that IT researchers at Trellix discovered a vulnerability in the decompression of .tar archives, which could allow attackers with crafted archives to overwrite files as root. The Trellix analysts wrote on Twitter that they were able to inject a backdoor shell that survives device restarts. Cisco has assigned a bug ID and confirmed the vulnerability, but argues that this is a future feature, is unsupported, and is currently not active. Therefore, there is no update to correct this error yet.

A reflected cross-site scripting vulnerability (CVE-2023-20068, CVSS 6.1, medium). A server-side request forgery vulnerability in the Cisco Identity Services Engine (ISE) allowed attackers to sniff out information (CVE-2023-20030, CVSS 6.0, medium). The Cisco ISE also contained three privilege escalation vulnerabilities (CVE-2023-20021, CVE-2023-20022, CVE-2023-20023, CVSS 6.0, medium)

Attackers could have paralyzed the system due to a path traversal vulnerability in Cisco’s Network Services Orchestrator, which enabled a Denial of Service (DoS) (CVE-2023-20040, CVSS 5.5, medium). Finally, Cisco reports vulnerabilities in the RV340, RV340W, RV345 and RV345P Dual WAN Gigabit VPN Routers that could allow attackers to upload arbitrary files. A firewall setting should prevent this. However, since the devices have already reached their end-of-life (EoL), Cisco does not provide updated firmware (CVE-2023-20073, CVSS 5.3, medium).

Cisco lists the security warnings on its own website. In it, the manufacturer explains whether temporary countermeasures or software updates are available to correct the errors.

Critical vulnerabilities in Cisco routers were recently discovered. Since these have already reached their EoL, there were no security updates from the manufacturer either.

(dmk)

To home page

Tags: backdoorCiscomultiplePatchespotentialproductsSecuritySecurity UpdatesVulnerabilitiesvulnerability

Related Posts

World

F1 2023 qualifying today at the Australian GP live | Formula 1 starting grid

by Kiratas
April 1, 2023
World

The price is bold, and sometimes justified – the photo news of week 13/2023

by Kiratas
April 1, 2023
World

F1 2023 qualifying today at the Australian GP live | Formula 1 starting grid

by Kiratas
April 1, 2023
World

Alcaraz falls exhausted before Sinner and gives up the Miami crown and number one

by Kiratas
April 1, 2023
World

Electric cars: Pre-heaters for the battery under test

by Kiratas
March 31, 2023
Next Post

This is the exact day on which the increase in the Minimum Interprofessional Wage will come into force

Electric speedboat Voltari 260: From Florida to the Bahamas on one charge

Why do our muscles ache if we have the flu?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • TikTok… globalization is running out of time
  • F1 2023 qualifying today at the Australian GP live | Formula 1 starting grid
  • The price is bold, and sometimes justified – the photo news of week 13/2023
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.