Security News
![Cisco Patches Critical Flaw After PoC Exploit Code Release](/static/build/img/news/cisco-patches-critical-flaw-after-poc-exploit-code-release.jpg)
A day after proof-of-concept exploit code was published for a critical flaw in Cisco Security Manager, Cisco has hurried out a patch. PoC exploits for the flaw - as well as 11 other issues in Cisco Security Manager - were published online Monday by security researcher Florian Hauser.
![Cisco Patches Publicly Disclosed Vulnerabilities in Security Manager](/static/build/img/news/alt/hackers-statistics-small.jpg)
Cisco this week released advisories for three serious vulnerabilities in Security Manager that already have proof-of-concept exploit code available online. Cisco says that there are no workarounds available for this vulnerability but that Cisco Security Manager 4.22 addresses is.
![Critical vulnerabilities in Cisco Security Manager fixed, researcher discloses PoCs](/static/build/img/news/alt/managed-security-small.jpg)
Cisco has patched two vulnerabilities in its Cisco Security Manager solution, both of which could allow unauthenticated, remote attackers to gain access to sensitive information on an affected system. Those are part of a batch of twelve vulnerabilities flagged in July 2020 by Florian Hauser, a security researcher and red teamer at Code White.
![Researcher Discloses Critical RCE Flaws In Cisco Security Manager](/static/build/img/news/researcher-discloses-critical-rce-flaws-in-cisco-security-manager.jpg)
Cisco has published multiple security advisories concerning critical flaws in Cisco Security Manager a week after the networking equipment maker quietly released patches with version 4.22 of the platform. The flaws were responsibly reported to Cisco's Product Security Incident Response Team three months ago, on July 13.
![High-Severity Cisco DoS Flaw Can Immobilize ASR Routers](/static/build/img/news/high-severity-cisco-dos-flaw-can-immobilize-asr-routers.jpg)
A high-severity flaw in Cisco's IOS XR software could allow unauthenticated, remote attackers to cripple Cisco Aggregation Services Routers. The flaw stems from Cisco IOS XR, a train of Cisco Systems' widely deployed Internetworking Operating System.
![Cisco Zero-Day in AnyConnect Secure Mobility Client Remains Unpatched](/static/build/img/news/cisco-zero-day-in-anyconnect-secure-mobility-client-remains-unpatched.jpg)
Cisco has disclosed a zero-day vulnerability - for which there is not yet a patch - in the Windows, macOS and Linux versions of its AnyConnect Secure Mobility Client Software. "Cisco plans to fix this vulnerability in a future release of Cisco AnyConnect Secure Mobility Client Software."
![Cisco Working on Patch for Code Execution Vulnerability in VPN Product](/static/build/img/news/alt/antivirus-stats-small.jpg)
Cisco informed customers on Wednesday that it's working on a patch for a code execution vulnerability affecting its AnyConnect product. According to the networking giant, the product is affected by a flaw, tracked as CVE-2020-3556, that can be exploited by a local, authenticated attacker to cause an AnyConnect user to execute a malicious script.
![Cisco discloses AnyConnect VPN zero-day, exploit code available](/static/build/img/news/alt/web-statistics-3-small.jpg)
Cisco has disclosed today a zero-day vulnerability in the Cisco AnyConnect Secure Mobility Client software with proof-of-concept exploit code publicly available. While security updates are not yet available for this arbitrary code execution vulnerability, Cisco is working on addressing the zero-day, with a fix coming in a future AnyConnect client release.
![Cisco Patches 17 High-Severity Vulnerabilities in Security Appliances](/static/build/img/news/alt/hackers-statistics-small.jpg)
Cisco on Wednesday announced the release of patches for 17 high-severity vulnerabilities in its security appliances as part of its Security Advisory Bundled Publication for October 2020. The vulnerabilities have been found to impact Adaptive Security Appliance, Firepower Threat Defense, and Firepower Management Center.
![Cisco Warns of Severe DoS Flaws in Network Security Software](/static/build/img/news/cisco-warns-of-severe-dos-flaws-in-network-security-software-small.jpg)
"The Cisco Product Security Incident Response Team is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory," according to Cisco in an update released on Wednesday. The most severe of these flaws includes a vulnerability in Cisco Firepower Chassis Manager, which exists in the Firepower Extensible Operating System and provides management capabilities.