A certificate-checking gap in Webex Meetings’ join process let a nearby network attacker hijack another user’s meeting-join attempt; Cisco has already fixed it server-side.
Posts tagged: Cisco
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Authenticated users of Cisco ISE and ISE-PIC can inject stored scripts or bypass permission checks to alter device configuration, with no workaround available until patched.
Cisco Catalyst Center Insufficient Access Control Vulnerability
An access-control gap in Cisco Catalyst Center lets an already-authenticated user reach an internal service’s repository and read or modify its data, but only where Disaster Recovery is switched on.
Cisco Catalyst SD-WAN Manager Arbitrary File Creation Vulnerability
An authenticated user with only low-level access to Cisco Catalyst SD-WAN Manager can abuse a flawed API to write files anywhere on the underlying system via directory traversal.
Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability
A low-privilege, read-only CLI user on Cisco Catalyst SD-WAN Manager can overwrite arbitrary files and escalate straight to root, with no workaround available other than upgrading.
Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability
Cisco Catalyst SD-WAN Manager fails to properly validate certificates for its Smart Licensing connections, letting an attacker positioned to intercept internet traffic read the credentials used to reach Cisco’s cloud services.
Cisco Duo Self-Service Portal Command Injection Vulnerability
An unauthenticated attacker could inject arbitrary commands into emails sent from Cisco Duo’s cloud-hosted self-service portal, letting them slip malicious content to unsuspecting recipients.
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
A crafted RADIUS authentication request sent to any network device using Cisco ISE for AAA can force the ISE process to reload, knocking out authentication network-wide with no login needed.
Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass Vulnerability
Missing signature checks during boot on these Catalyst switches let a privileged local user or someone with physical access plant code that survives reboots and undermines the secure boot chain of trust.
Cisco IOS Software Industrial Ethernet Switch Device Manager Privilege Escalation Vulnerability
An authenticated user with only mid-level access on Cisco Industrial Ethernet switches can send a crafted HTTP request to the Device Manager and gain full administrative control.