City
Epaper

CERT-In finds multiple vulnerabilities in Cisco products, advises users to update

By IANS | Updated: May 19, 2024 20:05 IST

New Delhi, May 19 The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics ...

Open in App

New Delhi, May 19 The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has issued an advisory over two serious vulnerabilities in networking giant Cisco products that could allow attackers to elevate privileges to root on the underlying operating system.

The vulnerabilities reported in the company's product 'ConfD CLI' could allow the authenticated, low-privileged, local attacker "to read and write arbitrary files as root or elevate privileges to root on the underlying operating system", CERT-In said in its latest advisory.

The 'Arbitrary File Read and Write Vulnerability' exists in ConfD CLI due to improper authorisation enforcement when specific CLI commands are used.

"An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments," the cyber agency said.

It also mentioned that the successful exploitation of this vulnerability could allow "the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user".

The second vulnerability 'Privilege Escalation' exists in the affected product due to an incorrect privilege assignment when specific CLI commands are used.

According to the cyber agency, an attacker could exploit this vulnerability by executing an affected CLI command. In addition, CERT-In advised users to apply appropriate updates as released by Cisco.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

Other Sports5th Test: Siraj castles Crawley as England reach 50/1, need 324 runs to secure series win

International"You have been gravely misled by Pakistani military leadership": Baloch leader to Trump, says oil reserves belong to Balochistan

InternationalPakistan's July inflation rises to 4.1 pc amid fuel, food price hikes

InternationalUAE cementing its leadership in maritime sector through high-impact local projects

CricketLancashire signs Ajeet Singh Dale on a three-year contract

Technology Realted Stories

TechnologyStates asked to undertake regular screening to tackle rising fatty liver disease: Nadda

TechnologyAgra-born man to fly on Blue Origin’s next flight to edge of space

TechnologyWhat is ISRO’s 10-day HOPE analogue mission in Ladakh

TechnologyNFDC launches free residential VFX, animation training for Northeast youth

TechnologyKharif sowing up 4 pc, agriculture gross value added may rise 4.5 pc: Report