Saturday, December 9, 2023

Cisco Security Updates – RCE Flaw in Cisco Industrial Network Director Let Hackers Gain Admin Level Access

Cisco released a security update to address multiple vulnerabilities that reside in Cisco utilities includes a remote code execution flaw that affected Cisco Industrial Network Director.

This new Cisco security updates release with the fixes for 9 vulnerabilities, in which, two vulnerabilities marked as high severity and rest of the 7 vulnerabilities are categorized under medium severity.

Remote code execution resides in software update feature of Cisco Industrial Network Director let remote attacker authenticate the system remotely to execute the arbitrary code and take full control of the vulnerable system.

“The vulnerability ( CVE-2019-1861) is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system”

Cisco fixed this vulnerability in its new software releases 1.6.0 for Cisco Industrial Network Director.

Another high severity vulnerability ( CVE-2019-1845) that affected Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway let attackers perform Denial of Service.

According to Cisco, This vulnerability affects the Cisco following products if users are running a vulnerable release:

  • Expressway Series configured for Mobile and Remote Access with IM&P Service (Releases X8.1 to X12.5.2)
  • TelePresence VCS configured for Mobile and Remote Access with IM&P Service (Releases X8.1 to X12.5.2)
  • Unified Communications Manager IM&P Service (multiple releases)

Fixed Vulnerabilities in This Cisco Security Updates

Cisco Industrial Network Director Remote Code Execution VulnerabilityHighCVE-2019-1861 
Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service VulnerabilityHighCVE-2019-1845 
Cisco Webex Meetings Server Information Disclosure VulnerabilityMediumCVE-2019-1868
Cisco TelePresence Video Communication Server and Cisco Expressway Series Server-Side Request Forgery VulnerabilityMediumCVE-2019-1872 
Cisco Unified Computing System BIOS Signature Bypass VulnerabilityMediumCVE-2019-1880 
Cisco IOS XR Software Secure Shell Authentication VulnerabilityMediumCVE-2019-1842 
Cisco Industrial Network Director Stored Cross-Site Scripting VulnerabilityMediumCVE-2019-1882 
Cisco Industrial Network Director Cross-Site Request Forgery Vulnerability MediumCVE-2019-1881 
Cisco Enterprise Chat and Email Cross-Site Scripting VulnerabilityMediumCVE-2019-1870 

Cisco advised affected users to apply these patches immediately to keep the network safe and secure.

The patches can be deployed through Patch Manager plus, where you can pre-built, tested, ready-to-deploy packages for your Enterprise network.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates, also you can take the Best Cybersecurity courses online to keep yourself updated.

Also Read:

Critical Vulnerability in Cisco Elastic Services Controller Let Hackers Take Full Control of the System Remotely

Cisco Fixed Routers Vulnerabilities that Allows Hackers to Run Remote Code with Root Access

Website

Latest articles

WordPress POP Chain Flaw Exposes Over 800M+ Websites to Attack

A critical remote code execution vulnerability has been patched as part of the Wordpress...

Russian Star Blizzard New Evasion Techniques to Hijack Email Accounts

Hackers target email accounts because they contain valuable personal and financial information. Successful email...

Exploitation Methods Used by PlugX Malware Revealed by Splunk Research

PlugX malware is sophisticated in evasion, as it uses the following techniques to avoid...

TA422 Hackers Attack Organizations Using Outlook & WinRAR Vulnerabilities

Hackers exploit Outlook and WinRAR vulnerabilities because these widely used software programs are lucrative...

Bluetooth keystroke-injection Flaw: A Threat to Apple, Linux & Android Devices

An unauthenticated Bluetooth keystroke-injection vulnerability that affects Android, macOS, and iOS devices has been...

Atlassian Patches RCE Flaw that Affected Multiple Products

Atlassian has been discovered with four new vulnerabilities associated with Remote Code Execution in...

Reflectiz Introduces AI-powered Insights on Top of Its Smart Alerting System

Reflectiz, a cybersecurity company specializing in continuous web threat management, proudly introduces a new...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Endpoint Strategies for 2024 and beyond

Converge and Defend

What's the pulse of Unified Endpoint Management and Security (UEMS) in Europe? Join us live to uncover the strategies that are defining endpoint security in the region.

Related Articles