• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cisco releases urgent patch to fix critical flaw in emergency

Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems

You are here: Home / General Cyber Security News / Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems
October 5, 2023

Cisco has launched updates to deal with a critical security flaw impacting Crisis Responder that makes it possible for unauthenticated, distant attackers to sign into prone devices applying tough-coded qualifications.

The vulnerability, tracked as CVE-2023-20101 (CVSS rating: 9.8), is due to the presence of static person credentials for the root account that the corporation mentioned is commonly reserved for use throughout advancement.

“An attacker could exploit this vulnerability by utilizing the account to log in to an afflicted method,” Cisco explained in an advisory. “A effective exploit could allow for the attacker to log in to the affected system and execute arbitrary commands as the root user.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The issue impacts Cisco Unexpected emergency Responder Release 12.5(1)SU4 and has been addressed in edition 12.5(1)SU5. Other releases of the solution are not impacted.

Cybersecurity

The networking products big reported it found the dilemma through inside security testing and that it can be not knowledgeable of any destructive use of the vulnerability in the wild.

The disclosure comes much less than a week following Cisco warned of tried exploitation of a security flaw in its IOS Software package and IOS XE Software (CVE-2023-20109, CVSS score: 6.6) that could allow an authenticated remote attacker to attain remote code execution on affected methods.

In the absence of momentary workarounds, prospects are advised to update to the most recent model to mitigate opportunity threats.

Uncovered this article intriguing? Adhere to us on Twitter  and LinkedIn to browse additional exclusive content material we submit.


Some components of this article are sourced from:
thehackernews.com

Previous Post: «analysis and config extraction of lu0bot, a node.js malware with Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities
Next Post: QakBot Threat Actors Still in Action, Using Ransom Knight and Remcos RAT in Latest Attacks qakbot threat actors still in action, using ransom knight and»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.