Security News > 2020 > November > Critical vulnerabilities in Cisco Security Manager fixed, researcher discloses PoCs

Cisco has patched two vulnerabilities in its Cisco Security Manager solution, both of which could allow unauthenticated, remote attackers to gain access to sensitive information on an affected system.
Those are part of a batch of twelve vulnerabilities flagged in July 2020 by Florian Hauser, a security researcher and red teamer at Code White.
Cisco Security Manager is a security management application that provides insight into and control of Cisco security and network devices deployed by enterprises - security appliances, intrusion prevention systems, firewalls, routers, switches, etc.
Cisco has also simultaneously announced that it will fix multiple Java deserialization vulnerabilities in the upcoming v4.23 of the Cisco Security Manager solution.
The company's Product Security Incident Response Team has noted that public announcements about all these vulnerabilities are available, but that they are "Not aware" of instances of actual malicious use in the wild.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/oXirgwENL4M/
Related news
- Ongoing Cyber Attacks Exploit Critical Vulnerabilities in Cisco Smart Licensing Utility (source)
- OpenAI now pays researchers $100,000 for critical vulnerabilities (source)
- Still Using an Older Version of iOS or iPadOS? Update Now to Patch These Critical Security Vulnerabilities (source)
- Google paid $12 million in bug bounties last year to security researchers (source)
- GitLab patches critical authentication bypass vulnerabilities (source)
- Stealthy Apache Tomcat Critical Exploit Bypasses Security Filters: Are You at Risk? (source)
- Critical Cisco Smart Licensing Utility flaws now exploited in attacks (source)
- New Security Flaws Found in VMware Tools and CrushFTP — High Risk, PoC Released (source)
- Researchers Uncover 46 Critical Flaws in Solar Power Systems From Sungrow, Growatt, and SMA (source)
- Adobe Patches 11 Critical ColdFusion Flaws Amid 30 Total Vulnerabilities Discovered (source)