Menu
Cisco patches authentication, denial-of-service, NTP flaws in many products

Cisco patches authentication, denial-of-service, NTP flaws in many products

Remote attackers can bypass authentication on Cisco RV220W wireless network security firewalls

Cisco Systems has released a new batch of security patches this week for flaws affecting a wide range of products, including for a critical vulnerability in its RV220W wireless network security firewalls.

The RV220W vulnerability stems from insufficient input validation of HTTP requests sent to the firewall's Web-based management interface. This could allow remote unauthenticated attackers to send HTTP requests with SQL code in their headers that would bypass the authentication on the targeted devices and give attackers administrative privileges.

Cisco has patched this vulnerability in the 1.0.7.2 firmware version for RV220W devices. Manual workarounds include disabling the remote management functionality or restricting it to specific IP addresses.

The company also patched high- and medium-severity denial-of-service vulnerabilities in Cisco Wide Area Application Service (WAAS) appliances and modules, Cisco Small Business 500 Series switches and the SG300 managed switch. A cross-site scripting vulnerability was also patched in the Web-based management interface of Cisco Unity Connection.

Finally, the company imported patches for 12 vulnerabilities in the Network Time Protocol daemon (ntpd) that were fixed on Jan. 19 by the Network Time Foundation. These flaws can be exploited by attackers to modify the time on devices or to crash the ntpd process.

Having the correct time on system is very important for a variety of applications, including for security-sensitive operations.

The NTP flaws are suspected to affect over 70 Cisco products used for collaboration and social media products, network and security, routing and switching, unified computing and communications, streaming and transcoding, wireless and hosted services.

The company has published firmware updates for some of them as well as a list of affected products and available patches that it will likely update as it releases more fixes.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

The making of an MSSP: a blueprint for growth in NZ

The making of an MSSP: a blueprint for growth in NZ

Partners are actively building out security practices and services to match, yet remain challenged by a lack of guidance in the market. This exclusive Reseller News Roundtable - in association with Sophos - assessed the making of an MSSP, outlining the blueprint for growth and how partners can differentiate in New Zealand.

The making of an MSSP: a blueprint for growth in NZ
Reseller News Platinum Club celebrates leading partners in 2018

Reseller News Platinum Club celebrates leading partners in 2018

The leading players of the New Zealand channel came together to celebrate a year of achievement at the inaugural Reseller News Platinum Club lunch in Auckland. Following the Reseller News Innovation Awards, Platinum Club provides a platform to showcase the top performing partners and start-ups of the past 12 months, with more than ​​50 organisations in the spotlight.​​​

Reseller News Platinum Club celebrates leading partners in 2018
Meet the top performing HP partners in NZ

Meet the top performing HP partners in NZ

HP has honoured its leading partners in New Zealand during 2018, following 12 months of growth through the local channel. Unveiled during the fourth running of the ceremony in Auckland, the awards recognise and celebrate excellence, growth, consistency and engagement of standout Kiwi partners.

Meet the top performing HP partners in NZ
Show Comments