Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisco warns of a critical flaw affecting the On-Prem Smart Software Manager
Global Security

Cisco warns of a critical flaw affecting the On-Prem Smart Software Manager

AdminBy AdminJuly 18, 2024No Comments2 Mins Read
Cisco Switches Zero-Day
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 18, 2024Information hall

Smart Software Manager

Cisco has released patches to address a maximum severity security flaw affecting Smart Software Manager On-Prem (Cisco SSM On-Prem) that could allow a remote, unauthenticated attacker to change the password of any user, including those belonging to administrative users .

Vulnerability, tracked as CVE-2024-20419has a CVSS score of 10.0.

“This vulnerability is related to an incorrect implementation of the password change process,” the company said in a statement said in the consulting room. “An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access a web interface or API with the privileges of the compromised user.”

The vulnerability affects Cisco SSM On-Prem versions 8-202206 and earlier. This was fixed in version 8-202212. It should be noted that version 9 is not prone to flaws.

Cyber ​​security

Cisco said that there are no workarounds to address this issue, and that it is not aware of any malicious exploits in the wild. Security researcher Mohamed Adel is credited with discovering and reporting the bug.

CISA adds 3 deficiencies to the KEV catalog

The US Cyber ​​Security and Infrastructure Security Agency (CISA) reported this. added three vulnerabilities to its known exploits (KEV) catalog based on evidence of active operation –

  • CVE-2024-34102 (CVSS Score: 9.8) – Open Source Adobe Commerce and Magento Vulnerability. Invalid XML External Entity Reference (XXE) constraint
  • CVE-2024-28995 (CVSS Score: 8.6) – SolarWinds Serv-U Path Traversal Vulnerability
  • CVE-2022-22948 (CVSS Score: 6.5) – VMware vCenter Server Incorrect Default File Permissions Vulnerability

CVE-2024-34102, also called Cosmic Stingis a serious security flaw caused by improper handling of nested deserialization, which allows attackers to achieve remote code execution. A proof-of-concept (PoC) exploit for the flaw was released from Assetnote late last month.

Reports on exploitation CVE-2024-28995end-of-directory vulnerability that could allow access to sensitive files on the host machine in detail by GreyNoise, including attempts to read files such as /etc/passwd.

On the other hand, the abuse of CVE-2022-22948 was attributed to Google-owned Mandiant for China’s cyber espionage group known as UNC3886, which has a history of exploiting zero-day flaws in Fortinet, Ivanti and VMware devices.

To protect their networks from active threats, federal agencies must implement mitigations in accordance with vendor guidelines by August 7, 2024.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.