Cisco Warns of Severe DoS Flaws in Network Security Software

The majority of the bugs in Cisco’s Firepower Threat Defense (FTD) and Adaptive Security Appliance (ASA) software can enable denial of service (DoS) on affected devices. Continue reading Cisco Warns of Severe DoS Flaws in Network Security Software

Intel Releases Microcode Spectre Patches for Skylake CPUs

Intel continues to release CPU microcode updates that include mitigation for the Spectre vulnerability announced in January. This week the company released fixes for several CPUs on the Skylake platform. The company’s first batch of microcode upd… Continue reading Intel Releases Microcode Spectre Patches for Skylake CPUs

Cisco Patches Critical VPN Vulnerability

Cisco Systems released a patch Monday to fix a critical security vulnerability, with a CVSS rating of 10, in its Secure Sockets Layer VPN solution called Adaptive Security Appliance. Continue reading Cisco Patches Critical VPN Vulnerability

Cisco patches a perfect 10.0 ‘critical’ flaw in its popular security appliance

Cisco announced Monday a critical vulnerability in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) that allows an unauthenticated, remote attacker to execute code or cause a system reload. This flaw, a perfect 10.0 on Common Vulnerability Scoring System, tops out as the highest warning possible. The products a popular group of security devices designed to protect corporate networks and data centers. Users are urged to apply security updates that fix the issue. “The vulnerability is due to an attempt to double free a region of memory when the webvpn feature is enabled on the Cisco ASA device,” Cisco explained in the Monday announcement. “An attacker could exploit this vulnerability by sending multiple, crafted XML packets to a webvpn-configured interface on the affected system. An exploit could allow the attacker to execute arbitrary code and obtain full control of the system, or cause a reload of the affected device.” The vulnerability was found by Cedric […]

The post Cisco patches a perfect 10.0 ‘critical’ flaw in its popular security appliance appeared first on Cyberscoop.

Continue reading Cisco patches a perfect 10.0 ‘critical’ flaw in its popular security appliance