Saturday, April 1, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Cisco patches multiple products – potential backdoor vulnerability

Kiratas by Kiratas
February 3, 2023
in World
Reading Time: 2 mins read
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Cisco has found and patched vulnerabilities in several products. A total of six products are affected. In Cisco’s IOx Application Hosting Environment, one leak has a high risk rating and the others pose a medium threat.

Cisco: Affected Products

The vulnerability in Cisco’s IOx Application Hosting Environment could allow authenticated attackers from the network to execute arbitrary commands as root in the underlying operating system. The error is due to insufficient filtering of parameters when activating an application. Malicious actors could abuse this by distributing and activating an application with manipulated activation data (CVE-2023-20076, CVSS 7.2Risk “hoch“).

In the security advisory, Cisco mentions that IT researchers at Trellix discovered a vulnerability in the decompression of .tar archives, which could allow attackers with crafted archives to overwrite files as root. The Trellix analysts wrote on Twitter that they were able to inject a backdoor shell that survives device restarts. Cisco has assigned a bug ID and confirmed the vulnerability, but argues that this is a future feature, is unsupported, and is currently not active. Therefore, there is no update for this error.

A reflected cross-site scripting vulnerability (CVE-2023-20068, CVSS 6.1, medium). A server-side request forgery vulnerability in the Cisco Identity Services Engine (ISE) allowed attackers to sniff out information (CVE-2023-20030, CVSS 6.0, medium). Cisco ISE also contained three privilege escalation vulnerabilities (CVE-2023-20021, CVE-2023-20022, CVE-2023-20023, CVSS 6.0, medium)

A path traversal vulnerability in Cisco’s Network Services Orchestrator could have been used by attackers to cripple the system, enabling a Denial of Service (DoS) (CVE-2023-20040, CVSS 5.5, medium). Finally, Cisco reports vulnerabilities in Cisco’s RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN routers that could allow attackers to upload arbitrary files. A firewall setting should be able to prevent this, but since the devices have already reached their end-of-life (EoL), Cisco does not provide updated firmware (CVE-2023-20073, CVSS 5.3, medium).

Cisco lists the security warnings on its own website. In it, the manufacturer explains whether temporary countermeasures or software updates are available to correct the errors.

Critical vulnerabilities in Cisco routers were recently discovered. Since these have already reached their EoL, there were no security updates from the manufacturer either.

(dmk)

To home page

Tags: backdoorCiscomultiplePatchespotentialproductsSecuritySecurity UpdatesVulnerabilitiesvulnerability

Related Posts

World

Alcaraz falls exhausted before Sinner and gives up the Miami crown and number one

by Kiratas
April 1, 2023
World

Electric cars: Pre-heaters for the battery under test

by Kiratas
March 31, 2023
World

Fires devour northern Spain: Asturias and Cantabria have more than 150 active sources

by Kiratas
March 31, 2023
World

The OK and KO of Saturday, April 1, 2023

by Kiratas
March 31, 2023
World

The Ibex 35 seeks to close its fifth consecutive day on the rise

by Kiratas
March 31, 2023
Next Post

Zara Home reduces the most elegant lamp for your home by 60 euros

Amazon closes 2022 with losses after the record profits of the previous year

Cisco patches multiple products - potential backdoor vulnerability

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million MotorBike.gr online photo result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • New EBAU: what language do we want future university students to speak?
  • Alcaraz falls exhausted before Sinner and gives up the Miami crown and number one
  • Electric cars: Pre-heaters for the battery under test
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.