Security News

Cisco Patches Code Execution Flaw in VPN Product 6 Months After Disclosure
2021-05-14 13:29

Cisco this week announced the availability of patches for a high-severity vulnerability in AnyConnect Secure Mobility Client that could be exploited for code execution. Initially disclosed in November 2020, the flaw affects the interprocess communication channel of the secure VPN application and could be abused by a local attacker to cause an AnyConnect user to run a malicious script.

Cisco to Acquire Vulnerability Management Firm Kenna Security
2021-05-14 12:45

Networking giant Cisco said Friday that it has agreed to acquire Kenna Security, a privately held cybersecurity company focused on vulnerability management technology. Santa Clara, Calif.-based Kenna provides a risk-based vulnerability management platform that helps organizations identify and determine which vulnerabilities pose the highest risk so that security teams don't waste valuable time on weaknesses that are unlikely to be exploited.

Cisco to acquire Kenna Security to help customers improve their security posture
2021-05-14 12:43

With this acquisition, Cisco will transform the way security and IT teams collaborate to reduce the attack surface and the time it takes to detect and respond. With Kenna's technology, Cisco Security will be combining threat and risk-based vulnerability management as part of the SecureX platform, expanding the platform experience and enabling comprehensive scorecards for security controls and threat response performance.

Cisco fixes 6-month-old AnyConnect VPN zero-day with exploit code
2021-05-13 14:31

Cisco has fixed a six-month-old zero-day vulnerability found in the Cisco AnyConnect Secure Mobility Client VPN software, with publicly available proof-of-concept exploit code. The company's AnyConnect Secure Mobility Client allows working on corporate devices connected to a secure Virtual Private Network through Secure Sockets Layer and IPsec IKEv2 using VPN clients available for all major desktop and mobile platforms.

Cisco HyperFlex web interface has critical flaw that lets attackers get root and execute arbitrary commands
2021-05-07 05:52

USENIX, the not-for-profit advanced computing association, has decided to put an end to its beloved LISA sysadmin conferences, at least as a standalone event. In an online announcement, the LISA steering committee said that after 35 years of producing the "Best systems engineering content" the event "Will no longer be scheduled as a standalone conference."

Cisco partners with Box to advance secure work in the cloud
2021-05-07 00:30

Building on the seamlessly integrated experience of Box and Webex, the two companies are introducing a new integration which will enable users to connect a Box folder of their choice within Webex messaging, and any content shared in the space will be securely added to the same Box folder. "We are thrilled to expand our partnership with Cisco as we continue to advance secure work in the Content Cloud," said Aaron Levie, Co-Founder and Chief Executive Officer of Box.

Critical Flaws Hit Cisco SD-WAN vManage and HyperFlex Software
2021-05-06 18:50

Networking equipment major Cisco has rolled out software updates to address multiple critical vulnerabilities impacting HyperFlex HX and SD-WAN vManage Software that could allow an attacker to perform command injection attacks, execute arbitrary code, and gain access to sensitive information. The HyperFlex HX command injection vulnerabilities, tracked as CVE-2021-1497 and CVE-2021-1498, affect all Cisco devices running HyperFlex HX software versions 4.0, 4.5, and those prior to 4.0.

Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks
2021-05-06 17:54

Cisco has addressed two critical security vulnerabilities in the SD-WAN vManage Software, one of which could allow an unauthenticated attacker to carry out remote code execution on corporate networks or steal information. The networking giant also disclosed a denial-of-service issue in vManage; and locally exploitable bugs that would allow an authenticated attacker to escalate privileges or gain unauthorized access to applications.

Cisco Patches Critical Flaws in SD-WAN, HyperFlex HX Products
2021-05-06 12:28

Cisco on Wednesday released patches to address tens of vulnerabilities across its product portfolio, including critical flaws in SD-WAN software and the HyperFlex HX data platform. Two critical vulnerabilities were patched in the SD-WAN vManage software, alongside three high-severity issues.

Cisco bugs allow creating admin accounts, executing commands as root
2021-05-05 18:51

Cisco has fixed critical SD-WAN vManage and HyperFlex HX software security flaws that could enable remote attackers to execute commands as root or create rogue admin accounts. Cisco SD-WAN vManage Software vulnerabilities patched today by Cisco could enable unauthenticated, remote attackers to execute arbitrary code or access sensitive information.