City
Epaper

Indian cyber agency finds multiple bugs in Cisco products

By IANS | Updated: April 27, 2024 16:00 IST

New Delhi, April 27 The Indian Computer Emergency Response Team (CERT-In) which comes under the Ministry of Electronics ...

Open in App

New Delhi, April 27 The Indian Computer Emergency Response Team (CERT-In) which comes under the Ministry of Electronics & Information Technology, has issued an advisory over three serious vulnerabilities in networking giant Cisco products that could allow hackers to gain access, infiltrate into computer systems and steal data.

The vulnerabilities reported in Cisco Adaptive Security Appliance (ASA) software and Cisco Firepower Threat Defense (FTD) software could allow attackers to execute arbitrary commands and code on the underlying operating system with root-level privileges, device to reload unexpectedly, resulting in a denial of service (DoS), CERT-In said in its latest advisory.

The 'Command Injection Vulnerability' exists in the reported software due to the contents of a backup file being improperly sanitised at restore time.

"An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device," the cyber agency said.

Another 'Denial of Service Vulnerability' exists due to incomplete error checking when parsing an HTTP header.

Attackers could use this vulnerability by "sending a crafted HTTP request to a targeted web server on a device" and the successful exploitation could allow them to cause a "DoS condition when the device reloads".

The third, 'Code Execution Vulnerability' exists due to improper validation of a file when it is read from system flash memory.

According to the cyber agency, an attacker could exploit this vulnerability by copying a "crafted file to the disk0: file system of an affected device".

In addition, CERT-In advised people to apply appropriate updates as released by Cisco.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

Other SportsPT Usha says Commonwealth Sport delegation "very happy" with Ahmedabad's for CWG 2030

International"India an important member of Pax Silica": US Under Secy Helberg pushes pro-innovation AI framework in meet with Misri

NationalNDRF retrieves capsized boat from Yamuna in Mathura; 10 dead, search for missing continues

NationalECI orders repoll in Assam's Karimganj North after post-poll scrutiny of records

International"Iran didn't start this war": Representative of Supreme Leader Abdul Majid Hakeem Ilahi

Technology Realted Stories

Technology4.05 lakh PNG connections gasified, not LPG: Petroleum Ministry

TechnologyCDS General Anil Chauhan calls for faster decisions in AI driven battlespace​

TechnologyJaipur students launch AI platform for defence families​

TechnologyIndia, Gulf nations align to safeguard trade flows, strengthen supply chains post-ceasefire

TechnologyAI to become integral to governance, must complement human intelligence: Dr Jitendra Singh