Cisco’s Smart Licensing Utility flaws suggest it’s pretty dumb on security

September 5, 2024 at 02:22PM Cisco’s Smart Licensing Utility has critical vulnerabilities, allowing remote attackers to access sensitive data and administer services without authentication. The flaws, rated 9.8/10 in severity, lack workarounds and are fixed through software updates. Customers are urged to patch immediately, ensuring legitimate software access. No known malicious activity has been reported. … Read more

Hello? Are you talking on a Cisco SPA300 or SPA500 IP phone? Now’s the time to junk ’em

August 8, 2024 at 08:35PM A BAE boffin discovered 3 critical flaws in Cisco’s Small Business SPA300 and SPA500 IP phones, none of which will be fixed. The flaws allow unauthenticated remote attackers to gain root privileges. Cisco won’t release updates as the products have entered the end-of-life process. No known exploits exist at this … Read more

China-Linked Volt Typhoon Hackers Possibly Targeting Australian, UK Governments

January 11, 2024 at 10:41AM Chinese state-sponsored hackers are targeting government entities in the US, UK, and Australia by exploiting old vulnerabilities in Cisco routers, reports SecurityScorecard. The actors likely compromised one-third of observed vulnerable devices and may operate a much larger botnet than previously believed, as indicated by connections to government sites. The attacks … Read more

Cisco patches IOS XE zero-days used to hack over 50,000 devices

October 23, 2023 at 10:09AM Cisco has released a free software update to address two vulnerabilities (CVE-2023-20198 and CVE-2023-20273) that hackers exploited to compromise over 50,000 IOS XE devices. The first fixed release available is 17.9.4a, with updates for other releases to be disclosed later. The vulnerabilities are in the web UI of Cisco devices … Read more