Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisco warns of a critical flaw affecting the On-Prem Smart Software Manager
Global Security

Cisco warns of a critical flaw affecting the On-Prem Smart Software Manager

AdminBy AdminJuly 18, 2024No Comments2 Mins Read
Cisco Switches Zero-Day
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 18, 2024Information hall

Smart Software Manager

Cisco has released patches to address a maximum severity security flaw affecting Smart Software Manager On-Prem (Cisco SSM On-Prem) that could allow a remote, unauthenticated attacker to change the password of any user, including those belonging to administrative users .

Vulnerability, tracked as CVE-2024-20419has a CVSS score of 10.0.

“This vulnerability is related to an incorrect implementation of the password change process,” the company said in a statement said in the consulting room. “An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an attacker to access a web interface or API with the privileges of the compromised user.”

The vulnerability affects Cisco SSM On-Prem versions 8-202206 and earlier. This was fixed in version 8-202212. It should be noted that version 9 is not prone to flaws.

Cyber ​​security

Cisco said that there are no workarounds to address this issue, and that it is not aware of any malicious exploits in the wild. Security researcher Mohamed Adel is credited with discovering and reporting the bug.

CISA adds 3 deficiencies to the KEV catalog

The US Cyber ​​Security and Infrastructure Security Agency (CISA) reported this. added three vulnerabilities to its known exploits (KEV) catalog based on evidence of active operation –

  • CVE-2024-34102 (CVSS Score: 9.8) – Open Source Adobe Commerce and Magento Vulnerability. Invalid XML External Entity Reference (XXE) constraint
  • CVE-2024-28995 (CVSS Score: 8.6) – SolarWinds Serv-U Path Traversal Vulnerability
  • CVE-2022-22948 (CVSS Score: 6.5) – VMware vCenter Server Incorrect Default File Permissions Vulnerability

CVE-2024-34102, also called Cosmic Stingis a serious security flaw caused by improper handling of nested deserialization, which allows attackers to achieve remote code execution. A proof-of-concept (PoC) exploit for the flaw was released from Assetnote late last month.

Reports on exploitation CVE-2024-28995end-of-directory vulnerability that could allow access to sensitive files on the host machine in detail by GreyNoise, including attempts to read files such as /etc/passwd.

On the other hand, the abuse of CVE-2022-22948 was attributed to Google-owned Mandiant for China’s cyber espionage group known as UNC3886, which has a history of exploiting zero-day flaws in Fortinet, Ivanti and VMware devices.

To protect their networks from active threats, federal agencies must implement mitigations in accordance with vendor guidelines by August 7, 2024.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025

Researchers in detail in detail decisively developing tactics as it expands its geographical volume

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.