Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Price Continues Struggle, But Miners Refuse To Sell bitcoin news
  • Robinhood Launching New Non-Custodial Web3 Crypto Wallet – Wallets Bitcoin News bitcoin news
  • Portugal to Tax Cryptocurrency Income According to Minister of Finance – News Bitcoin News bitcoin news
  • Majority of Russia’s Financial Pyramids in Q1 Linked to Crypto, Scammers Exploit Sanctions Topic – Bitcoin News bitcoin news
  • US Court Fines Bitmex’s Founders $30 Million for Operating Illegal Crypto Platform – Regulation Bitcoin News bitcoin news
  • The Latest Zcash Software Release Supports the Network’s ‘Largest Upgrade in History’ – Bitcoin News bitcoin news
  • Infinite Arcade Launches the Last Sale of the Gamer NFTs – Sponsored Bitcoin News bitcoin news
  • Tim Draper Bullish on Bitcoin Due to Its Inflation Hedge Traits – Bitcoin News bitcoin news

Cisco Issues Patches for 3 New Flaws Affecting Enterprise NFVIS Software

Posted on May 5, 2022 By root


Cisco Systems on Wednesday shipped security patches to contain three flaws impacting its Enterprise NFV Infrastructure Software (NFVIS) that could permit an attacker to fully compromise and take control over the hosts.

Tracked as CVE-2022-20777, CVE-2022-20779, and CVE-2022-20780, the vulnerabilities “could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM,” the company said.

Credited for discovering and reporting the issues are Cyrille Chatras, Pierre Denouel, and Loïc Restoux of Orange Group. Updates have been released in version 4.7.1.

The networking equipment company said the flaws affect Cisco Enterprise NFVIS in the default configuration. Details of the three bugs are as follows –

  • CVE-2022-20777 (CVSS score: 9.9) – An issue with insufficient guest restrictions that allows an authenticated, remote attacker to escape from the guest VM to gain unauthorized root-level access on the NFVIS host.
  • CVE-2022-20779 (CVSS score: 8.8) – An improper input validation flaw that permits an unauthenticated, remote attacker to inject commands that execute at the root level on the NFVIS host during the image registration process.
  • CVE-2022-20780 (CVSS score: 7.4) – A vulnerability in the import function of Cisco Enterprise NFVIS that could allow an unauthenticated, remote attacker to access system information from the host on any configured VM.

Also addressed by Cisco recently is a high-severity flaw in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15.

“This includes privilege level 15 access to the device using management tools like the Cisco Adaptive Security Device Manager (ASDM) or the Cisco Security Manager (CSM),” the company noted in an advisory for CVE-2022-20759 (CVSS score: 8.8).

Furthermore, Cisco last week issued a “field notice” urging users of Catalyst 2960X/2960XR appliances to upgrade their software to IOS Release 15.2(7)E4 or later to enable new security features designed to “verify the authenticity and integrity of our solutions” and prevent compromises.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Bitcoin Hashrate Soars To New All-Time High, Will Price Follow
Next Post: Lawmakers, SEC Commissioner Slam Chair Gensler for Focusing on Crypto Enforcement – Regulation Bitcoin News

Related Posts

  • Microsoft Documents Over 200 Cyberattacks by Russia Against Ukraine cyber security news
  • U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware cyber security news
  • Researchers Warn of ‘Raspberry Robin’ Malware Spreading via External Drives cyber security news
  • Microsoft Mitigates RCE Vulnerability Affecting Azure Synapse and Data Factory cyber security news
  • SEC Plans to Hire More Staff in Crypto Enforcement Unit to Fight Frauds cyber security news
  • Web Trackers Caught Intercepting Online Forms Even Before Users Hit Submit cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys
  • ETH Back Under $2,000 as Balenciaga Gains Lose Steam – Market Updates Bitcoin News

Recent Comments

No comments to show.
  • Crypto Has No Valuable Output — It’s Not Adding to Society Like Other Investments – Featured Bitcoin News bitcoin news
  • Ethereum Recovers But ETH Must Clear This Key Resistance bitcoin news
  • Terra Community Plans to Vote on Forking the Chain — Launch May Airdrop a Billion New Tokens to Network Participants – Bitcoin News bitcoin news
  • Senator Elizabeth Warren Demands Answers From Fidelity for Allowing Bitcoin in Retirement Plans – Featured Bitcoin News bitcoin news
  • Bitcoin Price Hits Three-Month Low, What’s Driving This? bitcoin news
  • Bitcoin Could See 10% Jump, As Volatility Drops To 18-Month Low bitcoin news
  • Fake Clickjacking Bug Bounty Reports: The Key Facts cyber security news
  • Citi, Wells Fargo, BNY Mellon Invest in Crypto Firm Talos as Institutional Adoption of Digital Assets Accelerates – Finance Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme