City
Epaper

Cisco patches critical bug in its Security Manager

By IANS | Updated: November 17, 2020 17:35 IST

New Delhi, Nov 17 Networking giant Cisco has disclosed a critical security vulnerability in Cisco Security Manager that ...

Open in App

New Delhi, Nov 17 Networking giant Cisco has disclosed a critical security vulnerability in Cisco Security Manager that could allow an unauthenticated, remote attacker to gain access to sensitive information.

The company said it has released software updates that address this vulnerability and there are no workarounds that address this vulnerability.

"An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to download arbitrary files from the affected device," the company warned in its latest security update.

"The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device".

This vulnerability affects Cisco Security Manager release 4.21 and earlier.

Cisco said a total of three security vulnerabilities have been fixed in version 4.22 of Cisco Security Manager which was released last week.

The company published the advisory after Florian Hauser of security firm Code White, who reported the bugs to Cisco, published proof of concept (PoC) exploits for 12 vulnerabilities affecting Cisco Security Manager, reports ZDNet.

Another bug in Cisco Security Manager releases 4.21 and earlier, tracked as CVE-2020-27125, could allow attackers to view insufficiently protected static credentials on the affected software.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

International"Important that we have such a good relationship": Zelenskyy thanks Trump for US weapons deal

InternationalUAE: Madhya Pradesh CM Mohan Yadav holds meeting with Tata Group

InternationalUAE: CM Mohan Yadav holds "great discussion" with e&, explores potential collaborations

CricketStokes jokingly reveals Archer watched highlights of Ganguly waving his jersey before delivering sizzling spell against India

InternationalCM Mohan Yadav meets LuLu Group director to discuss investment opportunities

Technology Realted Stories

TechnologyCorporate Bond issuances hit 4-year high in Q1, surpass Rs 3 lakh crore mark

TechnologyCentre to issue new guidelines to promote first-time exporters: Piyush Goyal

TechnologyOver 32 pc of global GCC talent is currently in India: FM Sitharaman

TechnologyHCL Technologies' Q1 net profit falls 10 pc to Rs 3,843cr; declares Rs 12 dividend per share

TechnologySilver hits fresh all-time high amid global trade tension, gold price surge