Cisco Systems Inc. has issued a patch for its Internetwork Operating System (IOS), closing a security hole attackers could use to bypass command authorization checks and gain escalated user privileges.
The
Requires Free Membership to View
|
||||
The San Jose, Calif.-based networking giant also warned that an authenticated user is automatically placed into the Tcl shell mode if a previous user goes into Tcl shell mode and terminates the session before leaving the Tcl shell mode. This could exacerbate the vulnerability, the company said.
The patch is the latest in a series of steps Cisco has taken to address security holes in the past week.
It patched two security holes in CallManager -- the software-based call-processing component of its IP telephony products -- and offered workarounds for a glitch in the (IOS) HTTP Server.
Security Management Strategies for the CIO
Join the conversationComment
Share
Comments
Results
Contribute to the conversation