Security News

Cisco SMB kit harbors cross-site scripting bug: One wrong link click... and that's your router pwned remotely
2020-07-02 13:00

Cisco has patched a cross-site scripting vulnerability in two VPN routers it sells to small businesses and branch offices. By default, the management feature is disabled for remote users, though it is enabled for people on the same LAN. "A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information," Cisco explained in its advisory yesterday.

Cisco Warns of High-Severity Bug in Small Business Switch Lineup
2020-07-01 21:02

Cisco Systems is warning of a high-severity flaw affecting more than a half-dozen of its small business switches. The flaw, which ranks 8.1 out of 10.0 on the CVSS scale, stems from use of weak entropy generation for session identifier values, a Wednesday Cisco security advisory said.

Used Cisco Webex recently? Memory vuln could have let remote attackers snoop on your meetings and files
2020-06-18 16:45

Cisco Webex suffered from a vuln that could have allowed an attacker to access any account by simply copy-pasting a unique session token into a browser string. Once the token was extracted from the dump file, researchers were able to make a crafted HTTP POST request to Webex's servers, mimicking a genuine connection attempt, which returned a one-time login ticket for live meetings.

Cisco Webex, Router Bugs Allow Code Execution
2020-06-18 16:18

Cisco is warning of three high-severity flaws in its popular Webex web conferencing app, including one that could allow an unauthenticated attacker to remotely execute code on impacted systems. "An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site," according to Cisco's security update.

Cisco Adds New Security Features to Webex, Patches Serious Vulnerabilities
2020-06-18 13:57

Cisco announced this week that it has added new security features to Webex and that it has also patched several high-severity vulnerabilities in the conferencing product. At its Cisco Live 2020 event, the networking giant informed customers that it has extended its data loss prevention retention, Legal Hold and eDiscovery features to Webex Meetings.

Using Cisco Webex for your video conferencing needs? Go patch!
2020-06-18 13:06

Cisco has released security updates for Cisco Webex Meetings and Cisco Webex Meetings Server that fix several remotely exploitable vulnerabilities, as well as one less severe one that could allow hackers to gain access to a target's Webex account. CVE-2020-3361 affects Cisco Webex Meetings sites and Cisco Webex Meetings Server and could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site.

Cisco SecureX included with all Cisco Security products to simplify and enhance customer experience
2020-06-18 01:30

Cisco announces the general availability globally of Cisco SecureX, the broadest and most integrated cloud-native security platform, included with all Cisco Security products to simplify and enhance the way customers manage security, on June 30, 2020. To address current and future security challenges, SecureX connects the breadth of Cisco's integrated security portfolio with customers' entire security infrastructure for a consistent and simplified experience.

NS1’s software-defined DDI solution now available on Cisco GPL
2020-06-18 00:45

NS1 announced that the company has joined the Cisco DevNet SolutionsPlus program, making its enterprise DNS, DHCP, and IP address management solution the first and only software-defined DDI solution available on Cisco's Global Price List. Inclusion in Cisco's DevNet SolutionsPlus program enables Cisco field teams and channel partners to incorporate NS1's DDI and external DNS solutions into their portfolio while providing customers with enhanced network visibility and control.

Used Cisco Webex recently? Memory vuln could have let remote attackers snoop on your meetings and files
2020-06-17 13:45

In 1965, Gordon Moore published a short informal paper, Cramming more components onto integrated circuits. Based on not much more but these few data points and his knowledge of silicon chip development - he was head of R&D at Fairchild Semiconductors, the company that was to seed Silicon Valley - he said that for the next decade, component counts by area could double every year.

Cisco Patches Dozen Vulnerabilities in Industrial Routers
2020-06-04 12:13

Cisco this week announced that it has patched tens of vulnerabilities in its IOS software, including a dozen security flaws that impact the company's industrial routers and switches. A dozen vulnerabilities appear to impact the company's industrial products.