<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; Privilege escalation</title>
	<atom:link href="http://www.ciscozine.com/tag/privilege-escalation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:24:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>July 2011: three Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:17:51 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=892</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability &#160; Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. Vulnerable Products [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute exploit</title>
		<link>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/</link>
		<comments>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 13:36:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[AnyConnect VPN Client]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=890</guid>
		<description><![CDATA[The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for this vulnerabilities. Below the source of the exploit (Only for test!). ## # $Id: cisco_anyconnect_exec.rb 12872 2011-06-06 20:15:51Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 16:27:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=886</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series Default Credentials Vulnerability in Cisco Network Registrar Default Credentials for root Account on the Cisco Media Experience Engine 5600 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Vulnerable Products The vulnerabilities described in this document apply to the Cisco AnyConnect Secure [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 02 May 2011 12:44:16 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=872</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Wireless LAN Controllers Denial of Service Vulnerability Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Unified Communications Manager (previously known as Cisco CallManager) contains the following vulnerabilities: Three denial of service (DoS) vulnerabilities that affect Session Initiation Protocol (SIP) services Directory transversal vulnerability Two SQL injection vulnerabilities Vulnerable Products The following products are affected by at least one of the vulnerabilities that are described in this advisory: Cisco Unified Communications Manager 6.x Cisco Unified Communications Manager 7.x Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/05/02/april-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>January 2011: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 09:48:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=857</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: Cisco Content Services Gateway Vulnerabilities Cisco Content Services Gateway Vulnerabilities A service policy bypass vulnerability exists in the Cisco Content Services Gateway &#8211; Second Generation (CSG2), which runs on the Cisco Service and Application Module for IP (SAMI). Under certain configurations this vulnerability could allow: Customers to access sites that would normally match a billing policy to be accessed without being charged to the end customer Customers to access sites that would normally be denied based on configured restriction policies Vulnerable Products To determine the version [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/02/03/january-2011-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 08:32:04 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=785</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Vulnerabilities in Cisco Unified Contact Center Express Cisco Application Extension Platform Privilege Escalation Vulnerability Vulnerabilities in Cisco Unified Contact Center Express Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure. Vulnerable Products The vulnerabilities described in this document affect the following products: Cisco UCCX versions 5.x, 6.x, and 7.x Cisco Customer Response [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 11:32:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=778</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco PGW Softswitch Multiple Vulnerabilities in Cisco Network Building Mediator Multiple Vulnerabilities in Cisco PGW Softswitch Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. Successful exploitation of all but one of these vulnerabilities can crash the affected device. Exploitation of the remaining vulnerability will not crash the affected device, but it [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2010: three new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 08:45:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=766</guid>
		<description><![CDATA[On March 3 2010, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability Cisco Digital Media Manager Vulerabilities Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability A vulnerability exists in the Cisco Digital Media Player that could allow an unauthenticated attacker to inject video or data content into a remote display. Vulnerable Products Cisco Digital Media Player versions earlier than 5.2 are affected by this vulnerability. Details Cisco Digital Media Players are IP-based endpoints [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/03/08/march-2010-three-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2010: four new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 11:15:59 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=762</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories. Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities: TCP Connection Exhaustion Denial of Service Vulnerability Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability Crafted TCP Segment Denial of Service Vulnerability Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability NT LAN Manager version 1 (NTLMv1) Authentication Bypass [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/</link>
		<comments>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 22:04:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=759</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories. Multiple Vulnerabilities in Cisco Unified MeetingPlace Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime Vulnerable Products Cisco Unified MeetingPlace versions 5, 6, and 7 are each affected by at least one of the vulnerabilities described in this document. Details This Security Advisory describes multiple distinct vulnerabilities in the MeetingPlace and MeetingTime products. These vulnerabilities are independent [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerabilities in Unified Contact Center Express Administration Pages</title>
		<link>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/</link>
		<comments>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 09:09:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=723</guid>
		<description><![CDATA[Reported to Cisco by National Australia Bank&#8217;s Security Assurance team, on July 15, 2009 the PSIRT has published a new security advisory concerning to vulnerabilities in Unified Contact Center Express Administration Pages. Cisco Unified Contact Center Express (Cisco Unified CCX) server contains both a directory traversal vulnerability and a script injection vulnerability in the administration pages of the Customer Response Solutions (CRS) and Cisco Unified IP Interactive Voice Response (Cisco Unified IP IVR) products. Exploitation of these vulnerabilities could result in a denial of service condition, information disclosure, or a privilege escalation attack. Vulnerable Products All versions of Cisco Unified [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/07/20/vulnerabilities-in-unified-contact-center-express-administration-pages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jun.24, 2009: 2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 06:52:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=715</guid>
		<description><![CDATA[On June 24, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories. 1) Cisco Physical Access Gateway Denial of Service Vulnerability A denial of service (DoS) vulnerability exists in the Cisco Physical Access Gateway. There are no workarounds available to mitigate the vulnerability. This vulnerability has been corrected in Cisco Physical Access Gateway software version 1.1. Cisco has released free software updates that address this vulnerability. Vulnerable Products Cisco Physical Access Gateway running software versions prior to 1.1 are vulnerable. Details The Cisco Physical Access Gateway is the primary means for the Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mar.25, 2009?! 8 new Cisco vulnerability advisories!</title>
		<link>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/</link>
		<comments>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:12:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=701</guid>
		<description><![CDATA[On March 25, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 8 new vulnerability advisories. Mainly these vulnerabilities are DOS attack.   1) Cisco IOS cTCP Denial of Service Vulnerability A series of TCP packets may cause a denial of service (DoS) condition on Cisco IOS devices that are configured as Easy VPN servers with the Cisco Tunneling Control Protocol (cTCP) encapsulation feature. Vulnerable Products Cisco IOS devices running versions 12.4(9)T or later and configured for Cisco Tunneling Control Protocol (cTCP) encapsulation for EZVPN server are vulnerable. Details The Cisco Tunneling Control Protocol (cTCP) feature is [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/03/27/mar25-2009-8-new-cisco-vulnerability-advisories/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/</link>
		<comments>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 09:19:11 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=697</guid>
		<description><![CDATA[On 4 March 2009 and on 11 March 2009, Cisco has published two new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack. 1) Cisco 7600 Series Router Session Border Controller Denial of Service Vulnerability A denial of service (DoS) vulnerability exists in the Cisco Session Border Controller (SBC) for the Cisco 7600 series routers. Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available. Vulnerable Products All Cisco ACE-based SBC modules running software versions prior to 3.0(2) are affected. Details The Session Border Controller (SBC) [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/03/20/2-new-cisco-critical-vulnerabilities-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/</link>
		<comments>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/#comments</comments>
		<pubDate>Thu, 26 Feb 2009 16:11:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=683</guid>
		<description><![CDATA[On 25 February 2009, Cisco has published three new security advisories, which can be exploited by malicious people to conduct a DOS attack or a Remote control attack. 1) Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine Cisco ACE Module and Cisco ACE 4710 Application Control Engine contain multiple vulnerabilities that, if exploited, can result in any of the following impacts: Administrative level access via default user names and passwords Privilege escalation A denial of service (DoS) condition [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/02/26/3-new-cisco-critical-vulnerabilities-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

