Cisco eliminated two dangerous vulnerabilities affecting the update feature in the Cisco Industrial Network Director…
Cisco IOS XE is a Linux kernel-based network operating system used on various enterprise-level routers and Cisco Catalyst switches. Versions of IOS, IOS XR and NX-OS are not affected.
“This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software with the HTTP Server feature enabled”, — inform in Cisco.
The cause of the problem is in insufficient protection of web-interface from CSRF.
Attacker could use it by forcing user to follow malicious link (for example, an exploit can be hidden in a malicious ad).
Read also: Cisco fixed dangerous vulnerabilities in its industrial and enterprise solutions
Since vulnerability can be exploited completely unnoticed, it is a very attractive tool for cybercriminals.
Successful exploitation of the vulnerability allows an attacker to perform any actions with the same rights that has the attacked user.
“If the user has administrator rights, an attacker can change the configuration, execute commands, or reboot the affected device”, – explained Cisco experts.
The only way to fix this vulnerability is to install the latest updates (only available to users with a valid license).
A PoC-exploit for vulnerability already exists, but no evidence of its exploitation in real attacks was found.
Source: https://tools.cisco.com
Chernars.com is a domain that tries to force you into subscribing to its browser notifications…
Eclipse-adblocker.pro is a site that tries to trick you into clik to its browser notifications…
Initiateadvancedcompletelythe-file.top is a site that tries to force you into subscribing to its browser notifications…
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…
Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…
Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…