Vancouver, Surrey Indian Community - BCIndian.com
| | | | | | | | | | | |
 


 

CERT-In finds multiple vulnerabilities in Cisco products, advises users to update

Author : IANS

Science/Tech Read Latest News and Articles

Share With Your Friends



Add an Article

View All Contributions

Add To My Favorite

Add A Picture

New Delhi, May 19 (IANS) The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has issued an advisory over two serious vulnerabilities in networking giant Cisco products that could allow attackers to elevate privileges to root on the underlying operating system.

The vulnerabilities reported in the company's product 'ConfD CLI' could allow the authenticated, low-privileged, local attacker "to read and write arbitrary files as root or elevate privileges to root on the underlying operating system", CERT-In said in its latest advisory.

The 'Arbitrary File Read and Write Vulnerability' exists in ConfD CLI due to improper authorisation enforcement when specific CLI commands are used.

"An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments," the cyber agency said.

It also mentioned that the successful exploitation of this vulnerability could allow "the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user".

The second vulnerability 'Privilege Escalation' exists in the affected product due to an incorrect privilege assignment when specific CLI commands are used.

According to the cyber agency, an attacker could exploit this vulnerability by executing an affected CLI command. In addition, CERT-In advised users to apply appropriate updates as released by Cisco.

--IANS

shs/vd


Copyright and Disclaimer: All news and images appearing in our news section, search engines and social media are provided by IANS. If you face any issues related to the content/images, please contact our news service provider directly. We are not liable/responsible for any content/images related to the news service provider.


Latest News

View More News


More News Articles

Dinesh Karthik posts emotional letter confirming retirement from cricket

Sonu Sood welcomes Naseeruddin Shah to sets of his directorial debut film 'Fateh'

Swastika Mukherjee expresses anger over not being able to cast her vote in Kolkata

Swastika Mukherjee expresses anger for not being able to cast her vote in Kolkata

Manoj Bajpayee graciously accepts Movified Best Actor Award for 'Sirf Ek Bandaa Kaafi Hai'