Express Computer
Home  »  News  »  Cisco patches critical bug in its Security Manager

Cisco patches critical bug in its Security Manager

0 107

Networking giant Cisco has disclosed a critical security vulnerability in Cisco Security Manager that could allow an unauthenticated, remote attacker to gain access to sensitive information.

The company said it has released software updates that address this vulnerability and there are no workarounds that address this vulnerability.

“An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to download arbitrary files from the affected device,” the company warned in its latest security update.

“The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device”.

This vulnerability affects Cisco Security Manager release 4.21 and earlier.

Cisco said a total of three security vulnerabilities have been fixed in version 4.22 of Cisco Security Manager which was released last week.

The company published the advisory after Florian Hauser of security firm Code White, who reported the bugs to Cisco, published proof of concept (PoC) exploits for 12 vulnerabilities affecting Cisco Security Manager, reports ZDNet.

Another bug in Cisco Security Manager releases 4.21 and earlier, tracked as CVE-2020-27125, could allow attackers to view insufficiently protected static credentials on the affected software.

–IANS

Get real time updates directly on you device, subscribe now.

Leave A Reply

Your email address will not be published.

LIVE Webinar

Digitize your HR practice with extensions to success factors

Join us for a virtual meeting on how organizations can use these extensions to not just provide a better experience to its’ employees, but also to significantly improve the efficiency of the HR processes
REGISTER NOW 

Stay updated with News, Trending Stories & Conferences with Express Computer
Follow us on Linkedin
India's Leading e-Governance Summit is here!!! Attend and Know more.
Register Now!
close-image
Attend Webinar & Enhance Your Organisation's Digital Experience.
Register Now
close-image
Enable A Truly Seamless & Secure Workplace.
Register Now
close-image
Attend Inida's Largest BFSI Technology Conclave!
Register Now
close-image
Know how to protect your company in digital era.
Register Now
close-image
Protect Your Critical Assets From Well-Organized Hackers
Register Now
close-image
Find Solutions to Maintain Productivity
Register Now
close-image
Live Webinar : Improve customer experience with Voice Bots
Register Now
close-image
Live Event: Technology Day- Kerala, E- Governance Champions Awards
Register Now
close-image
Virtual Conference : Learn to Automate complex Business Processes
Register Now
close-image