Cisco Issues IronPort Patch - Vulnerabilities exposed systems to remote crash and takeover
Cisco has issued a patch for vulnerabilities that exposed its IronPort AsyncOS software for the Cisco e-mail security appliance to cover denial-of-service and command injection problems.
The vulnerability, described here, exposed several IronPort components. Its Web framework would allow and authenticated remote user to execute arbitrary commands with elevated privileges.
“An authenticated but unprivileged attacker could exploit this vulnerability by sending a crafted URL to the affected system, or by convincing a valid user to click on a malicious URL. A successful exploit could allow an attacker with sufficient knowledge to take complete control of the affected device,” Cisco notes.
Cisco also notes that the IronPort spam quarantine and its management GUI are both vulnerable to denial-of-service attacks. The spam quarantine has an improper handling of TCP connection requests at high speed, while the GUI is vulnerable to DoS attacks on HTTP and HTTPS connections.
Cisco has patches available for affected software.
Facebook
Twitter
LinkedIn
Instagram
Call us today on 01283 576162 to talk directly to one of our server specialists
Who we are
Server Case are the UK's server case and components specialists, selling PC cases, server cases, 19" Rackmount cases, Backplane modules, mobile disk racks, externam disk boxes and power supplies. server systems and components with thousands of products available to purchase securely online.
UK's only authorised eCommerce reseller of server chassis to the general public & companies.
Latest News
Server Case UK Attains Asus Business Gold Partner Status.
Posted on: 7th Oct 2019
We are very proud to announce our appointment as an ASUS Business Gold Partner.We have successfully grown our sales of Asus server & workstation motherboards as well as server barebone and complete solutions with a variety of new customers from new markets.Our longstanding expertise in servers and rack mo... [...] Read more
Latest Blog
Intel Core Series vs AMD Ryzen
Posted on: 27th May 2020
The two major competitors in the processor market are undoubtably Intel and AMD. Server Case UK group will be comparing various Intel and AMD product ranges to the closest equivalent product range of the other manufacturer, to determine the differences between them and find what you should be using. This will... [...] Read more
Latest Video
View more of our reviews, unboxing and installation videos on YouTube.
Business Links
Site Information