More

    Cisco has patched a worrying flaw which could have let attackers hijack devices




    • Cisco has patched a 10/10 flaw in IOS XE Software for Wireless LAN Controllers
    • The flaw was due to hardcoded tokens
    • There is no evidence of abuse in the wild (yet)

    Cisco has released a patch for a maximum-severity flaw found in its IOS XE Software for Wireless LAN Controllers which could have allowed threat actors to take over vulnerable endpoints.

    The flaw is yet another case of hardcoded credentials, this time in the form of a JSON Web Token (JWT). “An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface,” it is explained in the NVD website. “A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.”

    https://cdn.mos.cms.futurecdn.net/4vPx4qpVwRADJoMvv3gttX.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img