It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Cisco firewall has a giant bug Cisco firewall has a giant bug
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Cisco firewall has a giant bug
Reply
 
Thread Tools
Old 28th January 2020, 08:09   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 149,092
Stefan Mileschin Freshly Registered
Default Cisco firewall has a giant bug

Lets hackers in and makes them a cup of tea

Cisco is urging customers to update its Firepower Management Centre software "after users informed it of a critical bug that attackers could exploit over the internet".

According to ZDNet, the flaw was found in the web-based management interface of its software. The bug has a severity rating of 9.8 out of a possible 10 which is when a bug is so big that it practically invites the hacker in, makes them a nice cup of tea and then offers them nubile dancing girls, for their pleasure.

The vulnerability is caused by a glitch in the way Cisco's software handles Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. Remote attackers could exploit the flaw by sending specially crafted HTTP requests to the device. Devices are vulnerable if they've been configured to authenticate users of the web interface through an external LDAP server.

How customers should remediate the issue will depend on which release of Firepower Management Center (FMC) they're running. There is no workaround, but hotfix patches are available for several new releases of FMC, and maintenance releases that address the flaw are scheduled for later this year. "Customers may install a fix either by upgrading to a fixed release or by installing a hotfix patch," Cisco notes...

If that doozy was not bad enough, Cisco also disclosed seven high-severity flaws and 19 medium-severity security issues.

This FMC critical flaw follows updates made available earlier this month for three critical flaws affecting Cisco's Data Center Network Manager software. The researcher who reported the flaw has released proof-of-concept exploit code, but Cisco says it is not aware of any malicious use of the flaws.

https://fudzilla.com/news/50188-cisc...as-a-giant-bug
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cisco throws weight behind firewall Stefan Mileschin WebNews 0 17th September 2014 07:14
Building a pfSense Firewall jmke WebNews 0 2nd November 2011 12:35
Getting around the Great Firewall of China jmke WebNews 0 4th August 2008 10:21
Firewall On a USB Key jmke WebNews 0 29th May 2007 22:40
New Windows Attack Can Disable Firewall jmke WebNews 0 31st October 2006 08:25
Building a Desktop Firewall jmke WebNews 0 5th August 2006 12:54
AlphaShield Professional Hardware Firewall Sidney WebNews 0 3rd July 2006 05:19
How Safe is Windows Firewall? jmke WebNews 0 14th August 2004 13:41
Norton Firewall Bosw8er Hardware/Software Problems, Bugs 12 29th October 2003 21:59
Netgear VPN Firewall/Router Dark Templar General Madness - System Building Advice 0 22nd August 2002 19:26

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 07:54.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO