More

    Cisco patches critical security issues, so update now




    • Cisco releases fix for two flaws in Identity Services Engine
    • The flaws allowed for remote code execution, sensitive data exfiltration, and more
    • The first clean version of Identity Services Engine is 3.4

    Cisco has released patches for two critical-severity vulnerabilities plaguing its Identity Services Engine (ISE) solution. Since the flaws can be abused to run arbitrary commands and steal sensitive information, Cisco urged its users to apply the fixes as soon as possible.

    In a security advisory, the networking giant first said it patched a “deserialization of user-supplied Java byte streams” vulnerability tracked as CVE-2025-20124, and given a severity score of 9.9/10 (critical). By sending a custom serialized Java object to an affected Cisco ISE API, an attacker could execute arbitrary commands and elevate privileges.

    https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img