<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; Security Advisory</title>
	<atom:link href="http://www.ciscozine.com/category/security-advisory/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Tue, 14 May 2013 10:33:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>April 2013: ten Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2013/05/02/april-2013-ten-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2013/05/02/april-2013-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 02 May 2013 12:34:25 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1084</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Multiple Vulnerabilities in Cisco NX-OS-Based Products Cisco Device Manager Command Execution Vulnerability Multiple Vulnerabilities in Cisco Unified Computing System Cisco Network Admission Control Manager SQL Injection Vulnerability Cisco TelePresence Infrastructure Denial of Service Vulnerability Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers Multiple Vulnerabilities in Cisco Firewall Services Module Software Multiple Vulnerabilities in Cisco ASA Software Cisco Prime Network Control Systems Database Default Credentials Vulnerability Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution Multiple Vulnerabilities in Cisco NX-OS-Based Products Cisco Nexus, Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2013/05/02/april-2013-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2013: seven Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2013/04/12/march-2013-seven-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2013/04/12/march-2013-seven-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 12 Apr 2013 10:52:43 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1072</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published seven important vulnerability advisories: Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability Cisco IOS Software Resource Reservation Protocol Denial of Service Vulnerability Cisco IOS Software IP Service Level Agreement Vulnerability Cisco IOS Software Smart Install Denial of Service Vulnerability Cisco IOS Software Protocol Translation Vulnerability Cisco IOS Software Network Address Translation Vulnerability Cisco IOS Software Internet Key Exchange Vulnerability Cisco IOS Software Zone-Based Policy Firewall Session Initiation Protocol Inspection Denial of Service Vulnerability Cisco IOS Software contains a memory leak vulnerability that could be [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2013/04/12/march-2013-seven-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2013: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2013/03/04/february-2013-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2013/03/04/february-2013-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 04 Mar 2013 19:02:02 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1065</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities Cisco Prime Central for Hosted Collaboration Solution Assurance Excessive CPU Utilization Vulnerability Cisco Unified Presence Server Denial of Service Vulnerability Cisco ATA 187 Analog Telephone Adaptor Remote Access Vulnerability Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities Cisco Unified Communications Manager contains two vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Exploitation of these vulnerabilities could cause an interruption of voice services. Vulnerable Products The following products are [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2013/03/04/february-2013-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2013: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2013/02/12/january-2013-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2013/02/12/january-2013-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 12 Feb 2013 12:05:14 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[H.323]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1041</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities Multiple Vulnerabilities in Cisco Wireless LAN Controllers Cisco ASA 1000V Cloud Firewall H.323 Inspection Denial of Service Vulnerability Cisco Prime LAN Management Solution Command Execution Vulnerability Cisco Unified IP Phone Local Kernel System Call Input Validation Vulnerability Portable SDK for UPnP Devices Contains Buffer Overflow Vulnerabilities The Portable Software Developer Kit (SDK) for Universal Plug-n-Play (UPnP) Devices contains a libupnp library, originally known as the Intel SDK for UPnP Devices, which is vulnerable to multiple stack-based buffer [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2013/02/12/january-2013-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2012: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/12/13/november-2012-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/12/13/november-2012-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 13 Dec 2012 11:59:52 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[ACS]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Ironport]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1028</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco IronPort Appliances Sophos Anti-Virus Vulnerabilities Cisco Secure Access Control System TACACS+ Authentication Bypass Vulnerability Cisco IronPort Appliances Sophos Anti-Virus Vulnerabilities Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Web Security Appliances (WSA) include versions of Sophos Anti-Virus that contain multiple vulnerabilities that could allow an unauthenticated, remote attacker to gain control of the system, escalate privileges, or cause a denial-of-service (DoS) condition. An attacker could exploit these vulnerabilities by sending malformed files to an appliance that is running Sophos Anti-Virus. The malformed files could [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/12/13/november-2012-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2012: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/11/12/october-2012-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/11/12/october-2012-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 12 Nov 2012 13:06:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1014</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Multiple Vulnerabilities in Cisco Firewall Services Module Multiple Vulnerabilities in the Cisco WebEx Recording Format Player Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing Cisco Prime Data Center Network Manager Remote Command Execution Vulnerability Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Cisco ASA 5500 Series Adaptive Security Appliances (ASA) and Cisco Catalyst 6500 Series ASA Services Module [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/11/12/october-2012-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2012: eleven Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/10/18/september-2012-eleven-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/10/18/september-2012-eleven-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 18 Oct 2012 18:43:57 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[DHCP server]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[NAT]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=1010</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published eleven important vulnerability advisories: Cisco IOS Software Network Address Translation Vulnerabilities Cisco IOS Software Intrusion Prevention System Denial of Service Vulnerability Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability Cisco IOS Software DHCP Denial of Service Vulnerability Cisco IOS Software Tunneled Traffic Queue Wedge Vulnerability Cisco Catalyst 4500E Series Switch with Cisco Catalyst Supervisor Engine 7L-E Denial of Service Vulnerability Cisco IOS Software DHCP Version 6 Server Denial of Service Vulnerability Cisco IOS Software Malformed Border Gateway [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/10/18/september-2012-eleven-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2012: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/08/08/july-2012-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/08/08/july-2012-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 08 Aug 2012 06:31:33 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=991</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices Multiple Vulnerabilities in Cisco TelePresence Manager Multiple Vulnerabilities in Cisco TelePresence Recording Server Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices Cisco TelePresence Endpoint devices contain the following vulnerabilities: Cisco TelePresence API Remote Command Execution Vulnerability Cisco TelePresence Remote Command Execution Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Vulnerable Products Cisco TelePresence Manager, Cisco TelePresence Recording Server, Cisco TelePresence Multipoint Switch, and Cisco TelePresence Immersive Endpoint System may [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/08/08/july-2012-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2012: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/07/04/june-2012-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/07/04/june-2012-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 04 Jul 2012 09:37:36 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[AnyConnect]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=986</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Cisco Application Control Engine Administrator IP Address Overlap Vulnerability Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Denial of Service Vulnerability Buffer Overflow Vulnerabilities in the Cisco WebEx Player The Cisco WebEx Recording Format (WRF) player contains four buffer overflow vulnerabilities and the Cisco Advanced Recording Format (ARF) player contains one buffer overflow vulnerability. In some cases, exploitation of the vulnerabilities could allow [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/07/04/june-2012-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2012: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2012/06/06/may-2012-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2012/06/06/may-2012-one-cisco-vulnerability/#comments</comments>
		<pubDate>Wed, 06 Jun 2012 06:08:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=983</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Cisco IOS XR Software Route Processor Denial of Service Vulnerability Cisco IOS XR Software Route Processor Denial of Service Vulnerability The vulnerability only exists on Cisco 9000 Series Aggregation Services Routers (ASR) Route Switch Processor (RSP440) and Cisco Carrier Routing System (CRS) Performance Route Processor (PRP). The vulnerability is a result of improper handling of crafted packets and could cause the route processor, which processes the packets, to be unable to transmit packets to the fabric. Vulnerable Products This vulnerability affects IOS XR Software version 4.2.0 [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/06/06/may-2012-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2012: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/#comments</comments>
		<pubDate>Thu, 03 May 2012 13:31:38 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=978</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Buffer Overflow Vulnerabilities in the Cisco WebEx Player The Cisco WebEx Recording Format (WRF) player contains three buffer overflow vulnerabilities. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user. Vulnerable Products The vulnerabilities disclosed in this advisory affect the Cisco WebEx Recording Format (WRF) player. The following client builds of Cisco WebEx Business Suite (WBS 27) are affected by at least [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/05/03/april-2012-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2012: twelve Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 10:03:25 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=950</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published twelve important vulnerability advisories: Cisco IOS Software Reverse SSH Denial of Service Vulnerability Cisco IOS Software RSVP Denial of Service Vulnerability Vulnerabilities in Cisco IOS Software Traffic Optimization Features Cisco IOS Software Multicast Source Discovery Protocol Vulnerability Cisco IOS Software Network Address Translation Vulnerability Cisco IOS Internet Key Exchange Vulnerability Cisco IOS Software Smart Install Denial of Service Vulnerability Cisco IOS Software Command Authorization Bypass Cisco IOS Software Zone-Based Firewall Vulnerabilities Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/04/02/march-2012-twelve-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2012: three Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:19:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=930</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IP Video Phone E20 Default Root Account Cisco Digital Media Manager Privilege Escalation Vulnerability Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) contain a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code with elevated privileges. Vulnerable Products The following Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) are affected by this vulnerability: Cisco IronPort Email [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:42:57 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=925</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Cisco Small Business SRP500 Series Command Injection Vulnerability Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Software that runs on Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series devices was updated to include secure default configurations beginning with the TC4.0 release. This change was accompanied by the release of Cisco Security Advisory cisco-sa-20110202-tandberg. Vulnerable Products All Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2011: ten Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:27:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=923</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Cisco Unified Contact Center Express Directory Traversal Vulnerability Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras Cisco Security Agent Remote Code Execution Vulnerabilities Cisco Unified Communications Manager Directory Traversal Vulnerability CiscoWorks Common Services Arbitrary Command Execution Vulnerability Cisco Show and Share Security Vulnerabilities Directory Traversal Vulnerability in Cisco Network Admission Control Manager Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Multiple Vulnerabilities in Cisco Firewall Services [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2011: fifteen Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:16:18 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Access-list]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=906</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published fifteen important vulnerability advisories: Cisco IOS Software IP Service Level Agreement Vulnerability Cisco Identity Services Engine Database Default Credentials Vulnerability Cisco IOS Software IPv6 over MPLS Vulnerabilities Cisco IOS Software IPv6 Denial of Service Vulnerability Cisco 10000 Series Denial of Service Vulnerability Cisco IOS Software Smart Install Remote Code Execution Vulnerability Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities Cisco IOS Software Data-Link Switching Vulnerability Cisco IOS Software Network Address Translation Vulnerabilities Cisco Unified Communications Manager Session Initiation Protocol Memory [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2011: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 12:59:48 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=894</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Apache HTTPd Range Header Denial of Service Vulnerability Denial of Service Vulnerability in Cisco TelePresence Codecs Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server Cisco Unified Communications Manager Denial of Service Vulnerabilities Denial of Service Vulnerabilities in Cisco Intercompany Media Engine Apache HTTPd Range Header Denial of Service Vulnerability The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. Vulnerable Products The following products are confirmed [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2011: three Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:17:51 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=892</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability &#160; Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. Vulnerable Products [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 16:27:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=886</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series Default Credentials Vulnerability in Cisco Network Registrar Default Credentials for root Account on the Cisco Media Experience Engine 5600 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Vulnerable Products The vulnerabilities described in this document apply to the Cisco AnyConnect Secure [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2011: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 06:58:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=877</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Cisco Content Delivery System Internet Streamer: Web Server Vulnerability Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities Cisco IOS XR Software IP Packet Vulnerability Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability Cisco IOS XR Software SSHv1 Denial of Service Vulnerability Cisco Content Delivery System Internet Streamer: Web Server Vulnerability The Cisco Internet Streamer application, part of the Cisco Content Delivery System (Cisco CDS), contains a vulnerability in its web server component that could cause the web server engine to crash when processing specially [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 May 2011 12:44:16 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=872</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Wireless LAN Controllers Denial of Service Vulnerability Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two SQL injection vulnerabilities Vulnerable Products The following products are affected by at least one of the vulnerabilities that are described in this advisory: Cisco Unified Communications Manager 6.x Cisco Unified Communications Manager 7.x Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 20:15:45 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=867</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco Network Admission Control Guest Server System Software Authentication Bypass Vulnerability Cisco Secure Access Control System Unauthorized Password Change Vulnerability Cisco Network Admission Control Guest Server System Software Authentication Bypass Vulnerability Cisco Network Admission Control (NAC) Guest Server system software contains a vulnerability in the RADIUS authentication software that may allow an unauthenticated user to access the protected network. Vulnerable Products This vulnerability affects all versions of NAC Guest Server software prior to software version 2.0.3. The software version is displayed on the login page of [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2011 Bundled Publication Deferred</title>
		<link>http://www.ciscozine.com/2011/03/22/march-2011-bundled-publication-deferred/</link>
		<comments>http://www.ciscozine.com/2011/03/22/march-2011-bundled-publication-deferred/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 10:37:12 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Earthquake]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=864</guid>
		<description><![CDATA[Cisco PSIRT regularly discloses vulnerabilities in Cisco IOS Software on the fourth Wednesday in March and September via the Cisco IOS Security Advisory bundle. The next bundled disclosure was planned for Wednesday, March 23, 2011, but Cisco will defer this disclosure until the next scheduled Cisco IOS bundle on September 28, 2011. Cisco has a long-standing policy of disclosing vulnerabilities to customers and the public simultaneously to ensure equal access to patched software. Based on recent events in Japan and eastern Asia, we are sensitive to the fact that customers globally are impacted directly or indirectly by these events and [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/03/22/march-2011-bundled-publication-deferred/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2011: nine Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 01 Mar 2011 08:19:29 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=862</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published nine important vulnerability advisories: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch Multiple Vulnerabilities in Cisco TelePresence Manager Multiple Vulnerabilities in Cisco TelePresence Recording Server Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Management Center for Cisco Security Agent Remote Code Execution Vulnerability Default Credentials for Root Account on Tandberg E, EX and C Series Endpoints Multiple Cisco WebEx Player Vulnerabilities Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch Multiple [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2011: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 09:48:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=857</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Cisco Content Services Gateway Vulnerabilities Cisco Content Services Gateway Vulnerabilities A service policy bypass vulnerability exists in the Cisco Content Services Gateway &#8211; Second Generation (CSG2), which runs on the Cisco Service and Application Module for IP (SAMI). Under certain configurations this vulnerability could allow: Customers to access sites that would normally match a billing policy to be accessed without being charged to the end customer Customers to access sites that would normally be denied based on configured restriction policies Vulnerable Products To determine the version [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco 2010 Annual Security Report</title>
		<link>http://www.ciscozine.com/2011/01/24/cisco-2010-annual-security-report/</link>
		<comments>http://www.ciscozine.com/2011/01/24/cisco-2010-annual-security-report/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 11:33:06 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Stories]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=853</guid>
		<description><![CDATA[The Cisco® Annual Security Report provides an overview of the combined security intelligence of the entire Cisco organization. The report encompasses threat information and trends collected between January and December 2010. It also provides a snapshot of the state of security for that period, with special attention paid to key security trends expected for 2011. In response to the last decade of cyber-exploits targeting PC operating systems, PC platform and application vendors have shored up security in their products and taken a more aggressive approach to patching vulnerabilities. As a result, scammers are finding it harder to exploit platforms that [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/01/24/cisco-2010-annual-security-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2010: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Nov 2010 10:53:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=827</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: CiscoWorks Common Services Arbitrary Code Execution Vulnerability CiscoWorks Common Services Arbitrary Code Execution Vulnerability CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator. Vulnerable Products CiscoWorks Common Services versions 3.0.5 and later are affected by this vulnerability. Versions 4.0 and later contain the fix. Administrators can check version details and licensing information about CiscoWorks Common Services by clicking the About button [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2010: seven Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/#comments</comments>
		<pubDate>Sat, 02 Oct 2010 20:25:26 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=816</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published seven important vulnerability advisories: Cisco IOS Software H.323 Denial of Service Vulnerabilities Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Cisco IOS Software Internet Group Management Protocol Denial of Service Vulnerability Cisco IOS Software Network Address Translation Vulnerabilities Cisco IOS SSL VPN Vulnerability Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities Multiple Vulnerabilities in Cisco Wireless LAN Controllers Cisco IOS Software H.323 Denial of Service Vulnerabilities The H.323 implementation in Cisco IOS Software contains two vulnerabilities that may be exploited remotely to cause a denial [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July &amp; August 2010: ten Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 15:30:40 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=794</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Cisco IOS XR Software Border Gateway Protocol Vulnerability Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Unified Presence Denial of Service Vulnerabilities Cisco IOS Software TCP Denial of Service Vulnerability Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine SQL Injection Vulnerability in Cisco Wireless Control System Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Multiple Vulnerabilities in Cisco Firewall Services Module CDS Internet Streamer: Web Server Directory Traversal Vulnerability Hard-Coded SNMP Community Names [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 08:32:04 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=785</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Vulnerabilities in Cisco Unified Contact Center Express Cisco Application Extension Platform Privilege Escalation Vulnerability Vulnerabilities in Cisco Unified Contact Center Express Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure. Vulnerable Products The vulnerabilities described in this document affect the following products: Cisco UCCX versions 5.x, 6.x, and 7.x Cisco Customer Response [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
