<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CiscoZine &#187; Remote Control</title>
	<atom:link href="http://www.ciscozine.com/tag/remote-control/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ciscozine.com</link>
	<description>Daily reporting on Cisco technology</description>
	<lastBuildDate>Wed, 08 Feb 2012 09:24:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>January 2012: three Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:19:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=930</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IP Video Phone E20 Default Root Account Cisco Digital Media Manager Privilege Escalation Vulnerability Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) contain a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code with elevated privileges. Vulnerable Products The following Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) are affected by this vulnerability: Cisco IronPort Email [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2012/02/01/january-2012-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:42:57 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=925</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Cisco Small Business SRP500 Series Command Injection Vulnerability Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series Device Default Root Account Manufacturing Error Software that runs on Cisco TelePresence System Integrator C Series and Cisco TelePresence EX Series devices was updated to include secure default configurations beginning with the TC4.0 release. This change was accompanied by the release of Cisco Security Advisory cisco-sa-20110202-tandberg. Vulnerable Products All Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/november-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2011: ten Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 16:27:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=923</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Buffer Overflow Vulnerabilities in the Cisco WebEx Player Cisco Unified Contact Center Express Directory Traversal Vulnerability Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras Cisco Security Agent Remote Code Execution Vulnerabilities Cisco Unified Communications Manager Directory Traversal Vulnerability CiscoWorks Common Services Arbitrary Command Execution Vulnerability Cisco Show and Share Security Vulnerabilities Directory Traversal Vulnerability in Cisco Network Admission Control Manager Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module Multiple Vulnerabilities in Cisco Firewall Services [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/12/02/october-2011-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco TelePresence exploits</title>
		<link>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/</link>
		<comments>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 06:55:58 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[TelePresence]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=909</guid>
		<description><![CDATA[Cisco TelePresence is an umbrella term for Video Conferencing Hardware and Software, Infrastructure and Endpoints. The C &#38; MXP Series are the Endpoints used on desks or in boardrooms to provide users with a termination point for Video Conferencing. 1. Post-authentication HTML Injection &#8211; CVE-2011-2544 (CSCtq46488): Cisco TelePresence Endpoints have a web interface (HTTP or HTTPS) for managing, configuring and reporting. It is possible to set the Call ID (with H.323 or SIP) to a HTML value. If a call is made to another endpoint and an authenticated user browses to the web interface on the endpoint receiving the call [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/24/cisco-telepresence-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2011: fifteen Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 20:16:18 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Access-list]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=906</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published fifteen important vulnerability advisories: Cisco IOS Software IP Service Level Agreement Vulnerability Cisco Identity Services Engine Database Default Credentials Vulnerability Cisco IOS Software IPv6 over MPLS Vulnerabilities Cisco IOS Software IPv6 Denial of Service Vulnerability Cisco 10000 Series Denial of Service Vulnerability Cisco IOS Software Smart Install Remote Code Execution Vulnerability Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities Cisco IOS Software Data-Link Switching Vulnerability Cisco IOS Software Network Address Translation Vulnerabilities Cisco Unified Communications Manager Session Initiation Protocol Memory [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/10/11/september-2011-fifteen-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>August 2011: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 12 Sep 2011 12:59:48 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=894</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Apache HTTPd Range Header Denial of Service Vulnerability Denial of Service Vulnerability in Cisco TelePresence Codecs Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server Cisco Unified Communications Manager Denial of Service Vulnerabilities Denial of Service Vulnerabilities in Cisco Intercompany Media Engine Apache HTTPd Range Header Denial of Service Vulnerability The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. Vulnerable Products The following products are confirmed [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/09/12/august-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July 2011: three Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 05 Aug 2011 13:17:51 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=892</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability &#160; Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. Vulnerable Products [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/08/05/july-2011-three-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute exploit</title>
		<link>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/</link>
		<comments>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/#comments</comments>
		<pubDate>Thu, 07 Jul 2011 13:36:01 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[AnyConnect VPN Client]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=890</guid>
		<description><![CDATA[The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for this vulnerabilities. Below the source of the exploit (Only for test!). ## # $Id: cisco_anyconnect_exec.rb 12872 2011-06-06 20:15:51Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions. Please see the Metasploit # Framework web site for more information on licensing and terms of [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/07/cisco-anyconnect-vpn-client-activex-url-property-download-and-execute-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Unified Operations Manager exploits</title>
		<link>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/</link>
		<comments>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 09:23:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Directory traversal vulnerability]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=889</guid>
		<description><![CDATA[Cisco Unified Operations Manager (CuOM) is a NMS for voice developed by Cisco Systems. Operations Manager monitors and evaluates the current status of both the IP communications infrastructure and the underlying transport infrastructure in your network. Multiple vulnerabilities have been identified in Cisco Unified Operations Manager and associated products. These vulnerabilities include: multiple blind SQL injections multiple XSS directory traversal vulnerability Below the source of the exploit (Only for test!). Blind SQL injection vulnerabilities that affect CuOM (CVE-2011-0960): The Variable CCMs of PRTestCreation can trigger a blind SQL injection vulnerability by supplying a single quote, followed by a time delay [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/06/cisco-unified-operations-manager-exploits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Security Agent Management Console ‘st_upload’ RCE Exploit</title>
		<link>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/</link>
		<comments>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 09:21:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Cisco Security Agent]]></category>
		<category><![CDATA[Code execution]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=888</guid>
		<description><![CDATA[Cisco Security Agent provides threat protection for server and desktop computing systems. Cisco Security Agent can function in a standalone manner or can be managed by the Management Center for Cisco Security Agent. The Management Center for Cisco Security Agent is affected by a vulnerability that could allow an unauthenticated attacker to perform remote code execution on the affected device. A successful exploit could allow the attacker to modify agent policies and system configuration and perform other administrative tasks. Note: This vulnerability can be exploited only by sending certain packets to the web management interface, which by default listens on [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/05/cisco-security-agent-management-console-%e2%80%98st_upload%e2%80%99-rce-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2011: four Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 16:27:41 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=886</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories: Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series Default Credentials Vulnerability in Cisco Network Registrar Default Credentials for root Account on the Cisco Media Experience Engine 5600 Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by the following vulnerabilities: Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Vulnerable Products The vulnerabilities described in this document apply to the Cisco AnyConnect Secure [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/07/04/june-2011-four-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2011: five Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 06:58:37 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=877</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published five important vulnerability advisories: Cisco Content Delivery System Internet Streamer: Web Server Vulnerability Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities Cisco IOS XR Software IP Packet Vulnerability Cisco XR 12000 Series Shared Port Adapters Interface Processor Vulnerability Cisco IOS XR Software SSHv1 Denial of Service Vulnerability Cisco Content Delivery System Internet Streamer: Web Server Vulnerability The Cisco Internet Streamer application, part of the Cisco Content Delivery System (Cisco CDS), contains a vulnerability in its web server component that could cause the web server engine to crash when processing specially [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/06/01/may-2011-five-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2011: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 05 Apr 2011 20:15:45 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=867</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco Network Admission Control Guest Server System Software Authentication Bypass Vulnerability Cisco Secure Access Control System Unauthorized Password Change Vulnerability Cisco Network Admission Control Guest Server System Software Authentication Bypass Vulnerability Cisco Network Admission Control (NAC) Guest Server system software contains a vulnerability in the RADIUS authentication software that may allow an unauthenticated user to access the protected network. Vulnerable Products This vulnerability affects all versions of NAC Guest Server software prior to software version 2.0.3. The software version is displayed on the login page of [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/04/05/march-2011-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2011: nine Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/#comments</comments>
		<pubDate>Tue, 01 Mar 2011 08:19:29 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=862</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published nine important vulnerability advisories: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch Multiple Vulnerabilities in Cisco TelePresence Manager Multiple Vulnerabilities in Cisco TelePresence Recording Server Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Management Center for Cisco Security Agent Remote Code Execution Vulnerability Default Credentials for Root Account on Tandberg E, EX and C Series Endpoints Multiple Cisco WebEx Player Vulnerabilities Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch Multiple [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2011/03/01/february-2011-nine-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>October 2010: one Cisco vulnerability</title>
		<link>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/</link>
		<comments>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/#comments</comments>
		<pubDate>Wed, 03 Nov 2010 10:53:21 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Buffer overflows]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=827</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory: CiscoWorks Common Services Arbitrary Code Execution Vulnerability CiscoWorks Common Services Arbitrary Code Execution Vulnerability CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator. Vulnerable Products CiscoWorks Common Services versions 3.0.5 and later are affected by this vulnerability. Versions 4.0 and later contain the fix. Administrators can check version details and licensing information about CiscoWorks Common Services by clicking the About button [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/11/03/october-2010-one-cisco-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Packet Tracer 5.2 DLL Hijacking Exploit</title>
		<link>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/</link>
		<comments>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 16:06:47 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Packet Tracer]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=817</guid>
		<description><![CDATA[Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .pkt or .pkz file. The vulnerability is caused due to the application loading libraries (e.g. wintab32.dll) in an insecure manner. The program uses a fixed path to look for specific files or libraries. This path includes directories that may not be trusted or under user control. By placing a custom version of the file or library in the path, the program [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/10/04/cisco-packet-tracer-5-2-dll-hijacking-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>September 2010: seven Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/#comments</comments>
		<pubDate>Sat, 02 Oct 2010 20:25:26 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=816</guid>
		<description><![CDATA[The Cisco Product Security Incident Response Team (PSIRT) has published seven important vulnerability advisories: Cisco IOS Software H.323 Denial of Service Vulnerabilities Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Cisco IOS Software Internet Group Management Protocol Denial of Service Vulnerability Cisco IOS Software Network Address Translation Vulnerabilities Cisco IOS SSL VPN Vulnerability Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerabilities Multiple Vulnerabilities in Cisco Wireless LAN Controllers Cisco IOS Software H.323 Denial of Service Vulnerabilities The H.323 implementation in Cisco IOS Software contains two vulnerabilities that may be exploited remotely to cause a denial [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/10/02/september-2010-seven-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>July &amp; August 2010: ten Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 15:30:40 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Inject data]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=794</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published ten important vulnerability advisories: Cisco IOS XR Software Border Gateway Protocol Vulnerability Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Unified Presence Denial of Service Vulnerabilities Cisco IOS Software TCP Denial of Service Vulnerability Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine SQL Injection Vulnerability in Cisco Wireless Control System Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Multiple Vulnerabilities in Cisco Firewall Services Module CDS Internet Streamer: Web Server Directory Traversal Vulnerability Hard-Coded SNMP Community Names [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/09/06/july-august-2010-ten-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>June 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 08:32:04 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=785</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Vulnerabilities in Cisco Unified Contact Center Express Cisco Application Extension Platform Privilege Escalation Vulnerability Vulnerabilities in Cisco Unified Contact Center Express Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure. Vulnerable Products The vulnerabilities described in this document affect the following products: Cisco UCCX versions 5.x, 6.x, and 7.x Cisco Customer Response [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/07/01/june-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 11:32:32 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=778</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Multiple Vulnerabilities in Cisco PGW Softswitch Multiple Vulnerabilities in Cisco Network Building Mediator Multiple Vulnerabilities in Cisco PGW Softswitch Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. Successful exploitation of all but one of these vulnerabilities can crash the affected device. Exploitation of the remaining vulnerability will not crash the affected device, but it [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/06/04/may-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>April 2010: two Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/04/22/april-2010-two-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/04/22/april-2010-two-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 10:21:51 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=773</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published two important vulnerability advisories: Cisco Secure Desktop ActiveX Control Code Execution Vulnerability Cisco Small Business Video Surveillance Cameras and Cisco 4-Port Gigabit Security Routers Authentication Bypass Vulnerability   Cisco Secure Desktop ActiveX Control Code Execution Vulnerability Cisco Secure Desktop contains a vulnerable ActiveX control that could allow an attacker to execute arbitrary code with the privileges of the user who is currently logged into the affected system. Cisco has released a free software update that addresses this vulnerability. Vulnerable Products Cisco Secure Desktop versions prior to 3.5.841 are affected. [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/04/22/april-2010-two-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>February 2010: four new Cisco vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 11:15:59 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=762</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published four important vulnerability advisories. Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Cisco ASA 5500 Series Adaptive Security Appliances are affected by the following vulnerabilities: TCP Connection Exhaustion Denial of Service Vulnerability Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability Crafted TCP Segment Denial of Service Vulnerability Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability NT LAN Manager version 1 (NTLMv1) Authentication Bypass [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/02/25/february-2010-four-new-cisco-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/</link>
		<comments>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 22:04:13 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=759</guid>
		<description><![CDATA[Recently, the The Cisco Product Security Incident Response Team (PSIRT) has published three important vulnerability advisories. Multiple Vulnerabilities in Cisco Unified MeetingPlace Multiple vulnerabilities exist in Cisco Unified MeetingPlace. This security advisory outlines the details of these vulnerabilities: Insufficient validation of SQL commands Unauthorized account creation User and password enumeration in Cisco MeetingTime Privilege escalation in Cisco MeetingTime Vulnerable Products Cisco Unified MeetingPlace versions 5, 6, and 7 are each affected by at least one of the vulnerabilities described in this document. Details This Security Advisory describes multiple distinct vulnerabilities in the MeetingPlace and MeetingTime products. These vulnerabilities are independent [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/02/03/3-new-cisco-critical-vulnerabilities-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Cisco WebEx WRF Player Vulnerabilities</title>
		<link>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 09:44:26 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>
		<category><![CDATA[WebEx]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=754</guid>
		<description><![CDATA[The The Cisco Product Security Incident Response Team (PSIRT) has published one important vulnerability advisory:  Multiple Cisco WebEx WRF Player Vulnerabilities. Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted user. The Cisco WebEx WRF Player is an application that is used to play back WebEx meeting recordings that have been recorded on the computer of an on-line meeting attendee. The WRF Player can be automatically installed when the user accesses a WRF file [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2010/01/05/multiple-cisco-webex-wrf-player-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sep.23, 2009: 11 new Cisco critical vulnerabilities!!</title>
		<link>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 10:00:44 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=733</guid>
		<description><![CDATA[On September 23, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 11 important vulnerability advisories. Cisco Unified Communications Manager Express Vulnerability Cisco IOS® devices that are configured for Cisco Unified Communications Manager Express (CME) and the Extension Mobility feature are vulnerable to a buffer overflow vulnerability. Successful exploitation of this vulnerability may result in the execution of arbitrary code or a Denial of Service (DoS) condition on an affected device. Vulnerable Products To determine the Cisco IOS Software release that is running on a Cisco product, administrators can log in to the device and issue the [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/09/25/sep-23-2009-11-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jul.29, 2009: 2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/08/13/jul29-2009-2-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/08/13/jul29-2009-2-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 10:31:54 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=729</guid>
		<description><![CDATA[On July 29, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories. 1) Active Template Library (ATL) Vulnerability Certain Cisco products that use Microsoft Active Template Libraries (ATL) and headers may be vulnerable to remote code execution. In some instances, the vulnerability may be exploited against Microsoft Internet Explorer to perform kill bit bypass. In order to exploit this vulnerability, an attacker must convince a user to visit a malicious web site. Vulnerable Products The following products are affected by this vulnerability:Cisco Unity 4.x, 5x., and 7.x Details Microsoft has identified vulnerabilities in [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/08/13/jul29-2009-2-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jun.24, 2009: 2 new Cisco critical vulnerabilities</title>
		<link>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/</link>
		<comments>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 06:52:28 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Privilege escalation]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=715</guid>
		<description><![CDATA[On June 24, 2009, the The Cisco Product Security Incident Response Team (PSIRT) has published 2 new vulnerability advisories. 1) Cisco Physical Access Gateway Denial of Service Vulnerability A denial of service (DoS) vulnerability exists in the Cisco Physical Access Gateway. There are no workarounds available to mitigate the vulnerability. This vulnerability has been corrected in Cisco Physical Access Gateway software version 1.1. Cisco has released free software updates that address this vulnerability. Vulnerable Products Cisco Physical Access Gateway running software versions prior to 1.1 are vulnerable. Details The Cisco Physical Access Gateway is the primary means for the Cisco [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/06/25/jun24-2009-2-new-cisco-critical-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CiscoWorks TFTP Directory Traversal Vulnerability</title>
		<link>http://www.ciscozine.com/2009/05/25/ciscoworks-tftp-directory-traversal-vulnerability/</link>
		<comments>http://www.ciscozine.com/2009/05/25/ciscoworks-tftp-directory-traversal-vulnerability/#comments</comments>
		<pubDate>Mon, 25 May 2009 18:11:49 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=712</guid>
		<description><![CDATA[CiscoWorks Common Services contains a vulnerability that could allow an unauthenticated remote attacker to access application and host operating system files. Cisco has released free software updates that address this vulnerability. A workaround that mitigates this vulnerability is available. Vulnerable Products Products that have TFTP services enabled and that run CiscoWorks Common Services versions 3.0.x, 3.1.x, and 3.2.x are vulnerable. Only CiscoWorks Common Services systems running on Microsoft Windows operating systems are affected. The following Cisco products that use CiscoWorks Common Services as their base are affected by this vulnerability. Cisco Unified Service Monitor versions 1.0, 1.1, 2.0, and 2.1 [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/05/25/ciscoworks-tftp-directory-traversal-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco ASA WebVPN Cross Site Scripting Vulnerability</title>
		<link>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/</link>
		<comments>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 13:30:15 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=707</guid>
		<description><![CDATA[Cisco ASA is prone to a cross-site scripting vulnerability. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials. Cisco ASA software versions 8.0.4(2B) and prior running on ASA 5500 Series Adaptive Security Appliances are vulnerable.   Test vulnerability: An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious HTTP request.   POST /+webvpn+/index.html HTTP/1.1 Host: "'&#62;&#60;script&#62;alert('BugsNotHugs')&#60;/script&#62;&#60;meta httpequiv="" content='"www.example.org Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */* Referer: https://www.example.com/+webvpn+/index.html Accept-Language: en-us Content-Type: [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/04/26/cisco-asa-webvpn-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple Vulnerabilities in Cisco ASA / PIX security</title>
		<link>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/</link>
		<comments>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 21:32:14 +0000</pubDate>
		<dc:creator>Fabio Semperboni</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Remote Control]]></category>

		<guid isPermaLink="false">http://www.ciscozine.com/?p=704</guid>
		<description><![CDATA[Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. Vulnerable Products The following is a list of the products affected by each vulnerability as described in detail within this advisory. VPN Authentication Bypass Vulnerability Cisco ASA or Cisco PIX security appliances that are configured for IPsec or SSL-based remote access VPN and have the Override Account Disabled feature enabled are affected by this vulnerability. Note:  The Override Account Disabled feature was introduced in Cisco ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1, 7.2, 8.0, and 8.1 are affected by [...]]]></description>
		<wfw:commentRss>http://www.ciscozine.com/2009/04/13/multiple-vulnerabilities-in-cisco-asa-pix-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

