HomeSecurityCisco fixes Security Manager vulnerabilities with public exploits

Cisco fixes Security Manager vulnerabilities with public exploits

Cisco has released some security updates to address several pre-authentication vulnerabilities with public exploits affecting Cisco Security Manager that could allow remote code execution after a successful exploitation.

Cisco Security Manager helps manage security policies across a wide variety of Cisco security and network devices and provides concise reporting and troubleshooting capabilities for security events. This product works with a wide range of Cisco security devices.

Cisco

Proof-of-concept exploits available (as of November)

These vulnerabilities affect versions 4.22 (and later) of Cisco Security Manager, which were released and disclosed by Cisco on November 16, after being reported by Code White security researcher Florian Hauser in August.

Hauser shared proof-of-concept exploits for all 12 Cisco Security Manager vulnerabilities that he reported after Cisco PSIRT stopped responding.

Fortunately, at this time, Cisco says it is not aware of any attack actively exploiting these vulnerabilities .

Security updates are available

Cisco has fixed these vulnerabilities in Cisco Security Manager Release 4.22 Service Pack 1.

Administrators should immediately deploy the security update as soon as possible, as there are no workarounds that address these security flaws.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS