Cisco License On-Prem espone il piano di controllo
NCSC-NL ha segnalato 8 vulnerabilità corrette in Cisco License On-Prem e Cisco Smart Software Manager On-Prem. Il punto non è un singolo bug di login: la superficie colpita è la web UI e le API di gestione, quindi un’istanza esposta può diventare un foothold sul piano di controllo.
Le falle consentono a un attaccante non autenticato di resettare password, scrivere file o causare DoS. Nei percorsi autenticati, un amministratore compromesso può arrivare all’esecuzione di comandi con privilegi root e leggere dati interni dal database. In pratica, il problema non si ferma alla disponibilità del servizio.
Cisco ha rilasciato aggiornamenti per le CVE elencate dal NCSC. Per chi espone questa interfaccia, anche solo in rete interna, il rischio resta quello di un server di supporto trattato come secondario ma capace di aprire l’accesso ai sistemi che amministra.
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges.
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthoriz
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review.
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), h