Cisco’s Customer Collaboration Platform chat interface fails to sanitise HTTP requests, letting an unauthenticated remote attacker craft requests that could redirect a user’s chat session to an attacker-controlled server.
Posts tagged: Cisco
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
Cloud deployments of Cisco ISE on AWS, Azure and OCI ship with the same static credentials across every instance of a given release and platform, letting anyone who knows them reach the admin node without authenticating.
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
Cisco Catalyst 9800 wireless controllers ship with a hard-coded authentication token in the AP file upload service, letting anyone reach the interface remotely without credentials and push files onto the controller.
Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025
A flaw in how Erlang/OTP’s SSH server handles authentication messages lets an unauthenticated remote attacker run code on affected Cisco products, with fixes staggered across trains through late 2025.
Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability
Unauthenticated attackers can crash the AnyConnect SSL VPN service on Meraki MX and Z Series gateways that use client certificate authentication, dropping every active remote-access session and blocking new ones.
ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
A crafted UDF file sent to Cisco Secure Endpoint Connector’s bundled ClamAV can crash the scanning process, halting file scans on Linux, Mac and Windows endpoints until it restarts.
Cisco Identity Services Engine Authorization Bypass Vulnerability
An authenticated attacker who reaches Cisco ISE’s admin web interface via SAML SSO can bypass authorisation checks on some administrative functions, including settings that trigger a device restart.
Cisco Identity Services Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco ISE’s admin web interface lets an authenticated admin plant script that runs in another admin’s session, exposing session data with no workaround available.
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
Certain Cisco Unified Communications Manager engineering-special builds ship with a hardcoded root SSH account that cannot be changed or removed, letting anyone reach it log straight in as root.
Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco ECE’s web UI lets an agent-credentialed attacker plant script that runs in a colleague’s session when they click a crafted link, but only if a specific rich text security setting is left disabled.