<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; Privilege escalation</title>
	<atom:link href="http://www.ciscozine.com/tag/privilege-escalation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Mon, 06 Sep 2010 15:30:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>June 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 08:32:04 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=785</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Application Extension Platform Privilege Escalation Vulnerability

Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:</p>
<ul>
<li>Vulnerabilities in Cisco Unified Contact Center Express</li>
<li>Cisco Application Extension Platform Privilege Escalation Vulnerability</li>
</ul>
<p><strong>Vulnerabilities in Cisco Unified Contact Center Express</strong><br />
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/">June 2010: two Cisco vulnerabilities</a> (623 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 11:32:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=778</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:

Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple Vulnerabilities in Cisco Network Building Mediator


Multiple Vulnerabilities in Cisco PGW Softswitch
Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are [...]]]></description>
			<content:encoded><![CDATA[<p>The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories:</p>
<ul>
<li>Multiple Vulnerabilities in Cisco PGW Softswitch</li>
<li>Multiple Vulnerabilities in Cisco Network Building Mediator</li>
</ul>
<p><strong><br />
Multiple Vulnerabilities in Cisco PGW Softswitch</strong><br />
Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. (...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/">May 2010: two Cisco vulnerabilities</a> (480 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2010: three new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:45:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=766</guid>
		<description><![CDATA[On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Manager Vulerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities

Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media [...]]]></description>
			<content:encoded><![CDATA[<p>On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories:</p>
<ul>
<li>Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability</li>
<li>Cisco Digital Media Manager Vulerabilities</li>
<li>Cisco Unified Communications Manager Denial of Service Vulnerabilities</li>
</ul>
<p><strong>Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability<br />
</strong>A vulnerability exists in the Cisco Digital Media Player that could allow an unauthenticated attacker to inject video or data content into a remote display.</p>
<p><strong>Vulnerable Products<br />
</strong>Cisco Digital Media Player versions earlier than 5.2 are affected by this vulnerability.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/">March 2010: three new Cisco vulnerabilities</a> (400 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/inject-data/" rel="tag">Inject data</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2010: four new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 11:15:59 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=762</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.
Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:

TCP Connection Exhaustion Denial of Service Vulnerability
Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities
Skinny Client Control Protocol (SCCP) [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories.</p>
<p><strong>Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances</strong><br />
Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities:</p>
<ul>
<li>TCP Connection Exhaustion Denial of Service Vulnerability</li>
<li>Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities</li>
<li>Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability</li>
<li>WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability</li>
<li>Crafted TCP Segment Denial of Service Vulnerability</li>
<li>Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability</li>
<li>NT LAN Manager version 1 (NTLMv1) Authentication Bypass Vulnerability</li>
</ul>
<p>These vulnerabilities are not interdependent; a release that is affected by one vulnerability is not necessarily affected by the others. There are workarounds for some of the vulnerabilities disclosed in this advisory.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/">February 2010: four new Cisco vulnerabilities</a> (1,191 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/</link>
		<comments>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 22:04:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=759</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.
Multiple Vulnerabilities in Cisco Unified MeetingPlace
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:

Insufficient validation of SQL commands
Unauthorized account creation
User and password enumeration in Cisco MeetingTime
Privilege escalation in Cisco MeetingTime

(...)Read the rest of [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories.</p>
<p><strong>Multiple Vulnerabilities in Cisco Unified MeetingPlace</strong><br />
Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities:</p>
<ul>
<li>Insufficient validation of SQL commands</li>
<li>Unauthorized account creation</li>
<li>User and password enumeration in Cisco MeetingTime</li>
<li>Privilege escalation in Cisco MeetingTime</li>
</ul>
<p><strong>(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/">3 new Cisco critical vulnerabilities</a> (762 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2010. |
<a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/">Permalink</a> |
<a href="http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerabilities in Unified Contact Center Express Administration Pages</title>
		<link>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/</link>
		<comments>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 09:09:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=723</guid>
		<description><![CDATA[Reported to Cisco by National Australia Bank&#8217;s Security Assurance team, on July 15, 2009 the PSIRT has published a new security advisory concerning to vulnerabilities in Unified Contact Center Express Administration Pages.
Cisco Unified Contact Center Express (Cisco Unified CCX) server contains both a directory traversal vulnerability and a script injection vulnerability in the administration pages [...]]]></description>
			<content:encoded><![CDATA[<p>Reported to Cisco by <strong>National Australia Bank&#8217;s Security Assurance team</strong>, on July 15, 2009 the PSIRT has published a new security advisory concerning to vulnerabilities in Unified Contact Center Express Administration Pages.</p>
<p>Cisco Unified Contact Center Express (Cisco Unified CCX) server contains both a directory traversal vulnerability and a script injection vulnerability in the administration pages of the Customer Response Solutions (CRS) and Cisco Unified IP Interactive Voice Response (Cisco Unified IP IVR) products. Exploitation of these vulnerabilities could result in a <strong>denial of service condition</strong>, <strong>information disclosure</strong>, or a <strong>privilege escalation attack</strong>.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/">Vulnerabilities in Unified Contact Center Express Administration Pages</a> (156 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jun.24, 2009: 2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 06:52:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=715</guid>
		<description><![CDATA[On June 24, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories.
1) Cisco Physical Access Gateway Denial of Service Vulnerability
A denial of service (DoS) vulnerability exists in the Cisco Physical Access Gateway. There are no workarounds available to mitigate the vulnerability. This vulnerability has been corrected in Cisco [...]]]></description>
			<content:encoded><![CDATA[<p>On June 24, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories.</p>
<p><strong>1) Cisco Physical Access Gateway Denial of Service Vulnerability</strong><br />
A denial of service (DoS) vulnerability exists in the Cisco Physical Access Gateway. There are no workarounds available to mitigate the vulnerability. This vulnerability has been corrected in Cisco Physical Access Gateway software version 1.1. Cisco has released free software updates that address this vulnerability.</p>
<p><strong>Vulnerable Products</strong><br />
Cisco Physical Access Gateway running software versions prior to 1.1 are vulnerable.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/">Jun.24, 2009: 2 new Cisco critical vulnerabilities</a> (484 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mar.25, 2009?! 8 new Cisco vulnerability advisories!</title>
		<link>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/</link>
		<comments>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:12:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=701</guid>
		<description><![CDATA[On March 25, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 8 new vulnerability advisories. Mainly these vulnerabilities are DOS attack.
 
1) Cisco IOS cTCP Denial of Service Vulnerability
A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers [...]]]></description>
			<content:encoded><![CDATA[<p>On March 25, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 8 new vulnerability advisories. Mainly these vulnerabilities are DOS attack.</p>
<p> </p>
<p><strong>1) Cisco IOS cTCP Denial of Service Vulnerability</strong><br />
A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers with the Cisco Tunneling Control Protocol (cTCP) encapsulation feature.</p>
<p><strong>Vulnerable Products<br />
</strong>Cisco IOS devices running versions 12.4(9)T or later and configured for Cisco Tunneling Control Protocol (cTCP) encapsulation for EZVPN server are vulnerable.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/">Mar.25, 2009?! 8 new Cisco vulnerability advisories!</a> (2,474 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/</link>
		<comments>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 09:19:11 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=697</guid>
		<description><![CDATA[On 4 March 2009 and on 11 March 2009, Cisco has published two new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
1) Cisco 7600 Series Router Session Border Controller Denial of Service Vulnerability
A denial of service (DoS) vulnerability exists in the Cisco Session Border Controller (SBC) for [...]]]></description>
			<content:encoded><![CDATA[<p>On 4 March 2009 and on 11 March 2009, Cisco has published two new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.</p>
<p><strong>1) Cisco 7600 Series Router Session Border Controller Denial of Service Vulnerability<br />
</strong>A denial of service (DoS) vulnerability exists in the Cisco Session Border Controller (SBC) for the Cisco 7600 series routers. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/">2 new Cisco critical vulnerabilities</a> (509 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/</link>
		<comments>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 16:11:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=683</guid>
		<description><![CDATA[On 25 February 2009, Cisco has published three new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.
1) Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine
The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application [...]]]></description>
			<content:encoded><![CDATA[<p>On 25 February 2009, Cisco has published three new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack.</p>
<p><strong>1) Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine</strong><br />
The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Cisco ACE Module and Cisco ACE 4710 Application Control Engine contain multiple vulnerabilities that, if exploited, can result in any of the following impacts:</p>
<ul>
<li>Administrative level access via default user names and passwords</li>
<li>Privilege escalation</li>
<li>A denial of service (DoS) condition(...)<br/>Read the rest of <a href="http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/">3 new Cisco critical vulnerabilities</a> (824 words)</p>
<hr />
<p><small>© Fabio Semperboni for <a href="http://www.ciscozine.com">CiscoZine</a>, 2009. |
<a href="http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/">Permalink</a> |
<a href="http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/#comments">No comment</a><br/>
Post tags: <a href="http://www.ciscozine.com/tag/dos/" rel="tag">DOS</a>, <a href="http://www.ciscozine.com/tag/privilege-escalation/" rel="tag">Privilege escalation</a>, <a href="http://www.ciscozine.com/tag/remote-control/" rel="tag">Remote Control</a><br/>
</small></p>]]></content:encoded>
			<wfw:commentRss>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
