ZeroHour

Search: “hijacking”

2 stories in the last 24h

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

Cisco patched Identity Services Engine flaws letting unauthenticated local attackers bypass 802.1X authentication or disclose sensitive information.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated local attacker to conduct an authentication bypass involving 802.1X session hijack or disclose sensitive information. Cisco has released software updates addressing these vulnerabilities. No workarounds are available. The advisory is part of a batch of Cisco releases.

Cisco Security Advisoriesupdated · 11m agofirst · 17h agoAdvisory 17 sources

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

Cisco patched an sftunnel flaw in Secure Firewall Management Center letting an authenticated remote attacker execute arbitrary commands as root.

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to execute commands as root. The flaw stems from incorrect permissions allowing a registered sftunnel peer to write an arbitrary file anywhere on the device, exploitable via connection hijacking or crafted sftunnel commands. Cisco has released software updates.

Cisco Security Advisories · 17h agoAdvisory 6 sources