Cisco IP Phone Harbors Critical RCE Flaw

Cisco stomped out a critical vulnerability in its IP Phone web server that could enable remote code execution by an unauthenticated attacker. Continue reading Cisco IP Phone Harbors Critical RCE Flaw

Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast

The researcher behind the five critical Cisco flaws, collectively called CDPwn, talks about why Layer 2 protocols are under-researched when it comes to security vulnerabilities. Continue reading Critical Cisco ‘CDPwn’ Protocol Flaws Explained: Podcast

Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

Cisco has released patches to address the five vulnerabilities, which could lead to remote code-execution and denial of service. Continue reading Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

Cisco has released patches to address the five vulnerabilities, which could lead to remote code-execution and denial of service. Continue reading Critical Cisco ‘CDPwn’ Flaws Break Network Segmentation

Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings

The flaw could allow a remote, unauthenticated attacker to enter a password-protected video conference meeting. Continue reading Cisco Webex Flaw Lets Unauthenticated Users Join Private Online Meetings

Cisco Aironet Access Points Plagued By Critical, High-Severity Flaws

Cisco has issued patches for critical and high-severity vulnerabilities in its Aironet access point devices. Continue reading Cisco Aironet Access Points Plagued By Critical, High-Severity Flaws

Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover

Cisco has patched a critical flaw in its virtualized function automation tool, Cisco Elastic Services Controller. Continue reading Critical Flaw in Cisco Elastic Services Controller Allows Full System Takeover

Cisco Patches High-Severity Flaws in IP Phones

The most serious vulnerabilities in Cisco’s 8800 Series IP Phones could allow unauthenticated, remote attackers to conduct a cross-site request forgery attack or write arbitrary files to the filesystem. Continue reading Cisco Patches High-Severity Flaws in IP Phones

Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers

Cisco said that CVE-2019-1663, which has a CVSS score of 9.8, allows unauthenticated, remote attackers to execute arbitrary code. Continue reading Cisco Fixes Critical Flaw in Wireless VPN, Firewall Routers