cis

Cisco Data Center Network Manager Unauthenticated Remote Code Execution

DCNM exposes a file upload servlet (FileUploadServlet) at /fm/fileUpload. An authenticated user can abuse this servlet to upload a WAR to the Apache Tomcat webapps directory and achieve remote code execution as root. This module exploits two other vulnerabilities, CVE-2019-1619 for authentication bypass on versions 10.4(2) and below, and CVE-2019-1622 (information disclosure) to obtain the correct directory for the WAR file upload. This module was tested on the DCNM Linux virtual appliance 10.4(2), 11.0(1) and 11.1(1), and should work on a few versions below 10.4(2). Only version 11.0(1) requires authentication to exploit (see References to understand why).






cis

Hacker War Drives San Francisco Cloning RFID Passports






cis

Cisco Security Advisory 20130206-ata187

Cisco Security Advisory - Cisco ATA 187 Analog Telephone Adaptor firmware versions 9.2.1.0 and 9.2.3.1 contain a vulnerability that could allow an unauthenticated, remote attacker to access the operating system of the affected device. Cisco has available free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.




cis

Cisco UCS Director Unauthenticated Remote Code Execution

The Cisco UCS Director virtual appliance contains two flaws that can be combined and abused by an attacker to achieve remote code execution as root. The first one, CVE-2019-1937, is an authentication bypass, that allows the attacker to authenticate as an administrator. The second one, CVE-2019-1936, is a command injection in a password change form, that allows the attacker to inject commands that will execute as root. This module combines both vulnerabilities to achieve the unauthenticated command injection as root. It has been tested with Cisco UCS Director virtual machines 6.6.0 and 6.7.0. Note that Cisco also mentions in their advisory that their IMC Supervisor and UCS Director Express are also affected by these vulnerabilities, but this module was not tested with those products.




cis

Cisco M1070 Content Security Management Appliance IronPort Header Injection

Cisco M1070 Content Security Management Appliance IronPort remote host header injection exploit.




cis

Cisco C170 Email Security Appliance 10.0.3-003 IronPort Header Injection

Cisco C170 Email Security Appliance version 10.0.3-003 IronPort remote host header injection exploit.




cis

Cisco Email Security Virtual Appliance C100V IronPort Header Injection

Cisco Email Security Virtual Appliance C100V IronPort remote host header injection exploit.




cis

Cisco C690 Email Security Appliance 11.0.2-044 IronPort Header Injection

Cisco C690 Email Security Appliance version 11.0.2-044 IronPort remote host header injection exploit.




cis

Cisco Email Security Virtual Appliance C600V IronPort Header Injection

Cisco Email Security Virtual Appliance C600V IronPort remote host header injection exploit.




cis

Cisco Email Security Virtual Appliance C370 IronPort Header Injection

Cisco Email Security Virtual Appliance C370 IronPort remote host header injection exploit.




cis

Cisco IronPort C350 Header Injection

Cisco IronPort C350 remote host header injection exploit.




cis

Cisco Content Security Management Virtual Appliance M600V IronPort Header Injection

Cisco Content Security Management Virtual Appliance M600V IronPort remote host header injection exploit.




cis

Cisco Email Security Virtual Appliance C300V IronPort Header Injection

Cisco Email Security Virtual Appliance C300V IronPort remote host header injection exploit.




cis

Cisco Email Security Virtual Appliance C380 IronPort Header Injection

Cisco Email Security Virtual Appliance C380 IronPort remote host header injection exploit.




cis

Cisco Device Hardcoded Credentials / GNU glibc / BusyBox

Many Cisco devices such as Cisco RV340, Cisco RV340W, Cisco RV345, Cisco RV345P, Cisco RV260, Cisco RV260P, Cisco RV260W, Cisco 160, and Cisco 160W suffer from having hard-coded credentials, known GNU glibc, known BusyBox, and IoT Inspector identified vulnerabilities.




cis

Cisco Content Security Virtual Appliance M380 IronPort Remote Cross Site Host Modification

Cisco Content Security Virtual Appliance M380 IronPort remote cross site host modification demo exploit.




cis

Cisco WLC 2504 8.9 Denial Of Service

Cisco WLC 2504 version 8.9 suffers from a denial of service vulnerability.




cis

Cisco DCNM JBoss 10.4 Credential Leakage

Cisco DCNM JBoss version 10.4 suffers from a credential leakage vulnerability.




cis

Cisco Discovery Protocol (CDP) Remote Device Takeover

Armis has discovered five critical, zero-day vulnerabilities in various implementations of the Cisco Discovery Protocol (CDP) that can allow remote attackers to completely take over devices.




cis

Cisco Data Center Network Manager 11.2 Remote Code Execution

Cisco Data Center Network Manager version 11.2 remote code execution exploit.




cis

Cisco Data Center Network Manager 11.2.1 SQL Injection

Cisco Data Center Network Manager version 11.2.1 suffers from a remote SQL injection vulnerability.




cis

Cisco Data Center Network Manager 11.2.1 Command Injection

Cisco Data Center Network Manager version 11.2.1 remote command injection exploit.




cis

Cisco Unified Contact Center Express Privilege Escalation

Cisco Unified Contact Center Express suffers from a privilege escalation vulnerability.




cis

Cisco IP Phone 11.7 Denial Of Service

Cisco IP Phone version 11.7 denial of service proof of concept exploit.




cis

Cisco AnyConnect Secure Mobility Client 4.8.01090 Privilege Escalation

Cisco AnyConnect Secure Mobility Client for Windows version 4.8.01090 suffer from a privilege escalation vulnerability due to insecure handling of path names.







cis

Delta Industrial Automation DCISoft 1.12.09 Stack Buffer Overflow

Delta Industrial Automation DCISoft version 1.12.09 suffers from a stack buffer overflow vulnerability.




cis

Despite criticism, solar roads remain part of Georgia sustainable highway lab

While solar roads have been criticized as impractical and inefficient, a Georgia foundation says they will continue to be part of its research lab for greener highways.




cis

San Francisco mulls creating its own 100 percent renewables-focused utility from PG&E wreckage

What happens when a famously left-leaning city dives into the buttoned-down business of electric utilities? San Francisco may soon find out.




cis

Mayor: PG&E assets are ‘great’ opportunity to bring clean energy to San Francisco

San Francisco Mayor London Breed wants to use PG&E Corp.’s bankruptcy to take over some of the company’s assets for the city’s power needs, a move that would shake up California’s largest utility and remake the state’s energy landscape.




cis

BMW M5 CS, Porsche Cayenne GTS Coupe, Porsche Track Precision App: Car News Headlines

BMW has been spotted testing what appears to be a new performance flagship for the M5 range. Word on the street is that the car, which will likely be dubbed an M5 CS, is powered by a newly developed V-8. Porsche looks to be readying a Cayenne GTS Coupe to help bridge the performance gap between the S and Turbo. The new variant should debut next...



  • Today in Car News

cis

Why More Solar and Wind on the Grid Should Be Driving Today’s Investment Decisions

A new LBNL report offers concrete suggestions about what investments today will be most beneficial in tomorrow’s renewable energy future.




cis

Despite criticism, solar roads remain part of Georgia sustainable highway lab

While solar roads have been criticized as impractical and inefficient, a Georgia foundation says they will continue to be part of its research lab for greener highways.




cis

Precision health strategy gets boost from Chinese gene sequencer

Chinese genome sequencing company, BGI Genomics (BGI), and Australian health-data expert, Pryzm Health (Pryzm) have announced a collaboration designed to bring genome-related precision health services to Australia.




cis

Cistri helps shape the cities and communities of Asia

Australian urban planning and design and economics consultancy Cistri is using its evidence-based insights to help Asian developers design and plan urban communities that enhance quality of life.




cis

San Francisco mulls creating its own 100 percent renewables-focused utility from PG&E wreckage

What happens when a famously left-leaning city dives into the buttoned-down business of electric utilities? San Francisco may soon find out.




cis

Mayor: PG&E assets are ‘great’ opportunity to bring clean energy to San Francisco

San Francisco Mayor London Breed wants to use PG&E Corp.’s bankruptcy to take over some of the company’s assets for the city’s power needs, a move that would shake up California’s largest utility and remake the state’s energy landscape.




cis

EU Leaders Said to Delay Decision on 2030 Targets for Emissions

European Union leaders intend next month to agree on a timeline for developing energy and climate targets for 2030, delaying a final decision on the polices, according to two people with knowledge of the matter.




cis

April 30, 2020 - IPC Provides Online Proctored Exams for CIT, CIS and CSE Certification




cis

San Francisco mulls creating its own 100 percent renewables-focused utility from PG&E wreckage

What happens when a famously left-leaning city dives into the buttoned-down business of electric utilities? San Francisco may soon find out.




cis

Mayor: PG&E assets are ‘great’ opportunity to bring clean energy to San Francisco

San Francisco Mayor London Breed wants to use PG&E Corp.’s bankruptcy to take over some of the company’s assets for the city’s power needs, a move that would shake up California’s largest utility and remake the state’s energy landscape.




cis

11. März 2020 - Precisionworks/Condunet in die Liste qualifizierter Hersteller nach IPC/WHMA-A-620 aufgenommen




cis

San Francisco Landing Pad

The Australian Landing Pad in San Francisco is located at WeWork, in the geographical and cultural heart of the new technology boom.




cis

[Coronavirus] EU criticised for giving in to Beijing censorship

The EU's foreign affairs chief Josep Borrell called agreeing to Chinese censorship on the origins of coronavirus "misguided". Nevertheless, he said diplomacy works like that in China.