Cisco patches critical flaws in Smart Licensing Utility and Identity Services Engine



Earlier this week, Cisco introduced new patches that fix bugs in different products, which allowed threat actors to log in to, or take over, vulnerable devices.

First, it addressed an OS command injection vulnerability, caused by insufficient validation of user-supplied input, found in Cisco’s Identity Service Engine (ISE). This one is tracked as CVE-2024-20469, and carries a severity score of 6.0. Cisco’s ISE is a network access control and policy management platform that enables organizations to enforce security policies across their network.

https://cdn.mos.cms.futurecdn.net/HNekN3koBpwwwTby8U44ik-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img