LIVE · cybersecurity feed
Live wire
ciscocritical

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software

Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

zeroday.news ·

Cisco has issued security updates to address a total of nine vulnerabilities impacting its Crosswork platforms and Secure Workload Software. Among these, five distinct flaws have been assigned a critical Common Vulnerability Scoring System (CVSS) score of 10.0, indicating the highest level of severity. The company’s advisory notes that the vulnerabilities affect specific components within the Crosswork suite, including Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, and are present regardless of the device’s configuration.

The critical vulnerabilities, by their nature, typically allow for unauthenticated, remote code execution or complete system compromise without user interaction. Such flaws often stem from issues like improper input validation, insecure deserialization, or buffer overflows in network-facing services. Exploitation of these types of vulnerabilities could grant an attacker full control over the affected system, enabling them to install malicious software, exfiltrate sensitive data, or disrupt operations.

Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning are components of Cisco’s network automation and assurance portfolio. These platforms are designed to provide real-time network visibility, analysis, and automated control for complex network environments. Secure Workload Software, formerly Tetration, focuses on workload protection and micro-segmentation across data centers and cloud environments, aiming to secure applications and data by enforcing granular access policies.

The broad impact across multiple Crosswork components, irrespective of configuration, suggests that the underlying issues might reside in shared libraries, core services, or fundamental architectural elements common to these platforms. Products in this category often handle sensitive network telemetry and control plane functions, making them high-value targets for attackers seeking to gain a foothold in an enterprise network or disrupt critical infrastructure.

Mitigation for this class of vulnerability invariably involves applying the vendor-supplied security patches as soon as possible. Organizations are typically advised to follow a robust patch management process, which includes testing updates in a staging environment before deploying them to production systems. Additionally, network segmentation, least-privilege access controls, and continuous monitoring for unusual activity can help limit the potential blast radius should an exploit occur before patches can be fully deployed.

The release of these patches underscores the ongoing challenge of securing complex enterprise software platforms that integrate diverse functionalities. Critical vulnerabilities in network infrastructure and workload security solutions highlight the importance of diligent security practices, both on the part of vendors in developing secure code and on the part of organizations in promptly applying security updates to protect their digital assets and operational continuity.

ciscovulnerabilitiescrossworksecure workloadpatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.