Cisco has patched a worrying flaw which could have let attackers hijack devices

zeeforce
3 Min Read




  • Cisco has patched a 10/10 flaw in IOS XE Software for Wireless LAN Controllers
  • The flaw was due to hardcoded tokens
  • There is no evidence of abuse in the wild (yet)

Cisco has released a patch for a maximum-severity flaw found in its IOS XE Software for Wireless LAN Controllers which could have allowed threat actors to take over vulnerable endpoints.

The flaw is yet another case of hardcoded credentials, this time in the form of a JSON Web Token (JWT). “An attacker could exploit this vulnerability by sending crafted HTTPS requests to the AP image download interface,” it is explained in the NVD website. “A successful exploit could allow the attacker to upload files, perform path traversal, and execute arbitrary commands with root privileges.”



Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights