Browsing articles tagged with " Privilege escalation"
Aug
5
2011

July 2011: three Cisco vulnerabilities

The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability

Jul
7
2011

Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute exploit

The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for this vulnerabilities. Below the source of the exploit (Only for test!).

Jul
4
2011

June 2011: four Cisco vulnerabilities

The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series Default Credentials Vulnerability in Cisco Network Registrar Default Credentials for root Account on the Cisco Media Experience Engine 5600

May
2
2011

April 2011: two Cisco vulnerabilities

The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Wireless LAN Controllers Denial of Service Vulnerability Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two SQL injection vulnerabilities

Feb
3
2011

January 2011: one Cisco vulnerability

The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Cisco Content Services Gateway Vulnerabilities Cisco Content Services Gateway Vulnerabilities A service policy bypass vulnerability exists in the Cisco Content Services Gateway – Second Generation (CSG2), which runs on the Cisco Service and Application Module for IP (SAMI). Under certain configurations this vulnerability could allow: Customers to access sites that would normally match a billing policy to be accessed without being charged to the end customer Customers to access sites that would normally be denied based on configured restriction policies

Jul
1
2010

June 2010: two Cisco vulnerabilities

The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Vulnerabilities in Cisco Unified Contact Center Express Cisco Application Extension Platform Privilege Escalation Vulnerability Vulnerabilities in Cisco Unified Contact Center Express Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure.

Jun
4
2010

May 2010: two Cisco vulnerabilities

The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco PGW Softswitch Multiple Vulnerabilities in Cisco Network Building Mediator Multiple Vulnerabilities in Cisco PGW Softswitch Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages.

Mar
8
2010

March 2010: three new Cisco vulnerabilities

On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability Cisco Digital Media Manager Vulerabilities Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability A vulnerability exists in the Cisco Digital Media Player that could allow an unauthenticated attacker to inject video or data content into a remote display. Vulnerable Products Cisco Digital Media Player versions earlier than 5.2 are affected by this vulnerability.

Feb
25
2010

February 2010: four new Cisco vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories. Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities: TCP Connection Exhaustion Denial of Service Vulnerability Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability Crafted TCP Segment Denial of Service Vulnerability Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability NT LAN Manager version 1 (NTLMv1) Authentication Bypass [...]

Feb
3
2010

3 new Cisco critical vulnerabilities

Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories. Multiple Vulnerabilities in Cisco Unified MeetingPlace Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime

Pages:12»