Cisco Issues IronPort Patch - Vulnerabilities exposed systems to remote crash and takeover
Cisco has issued a patch for vulnerabilities that exposed its IronPort AsyncOS software for the Cisco e-mail security appliance to cover denial-of-service and command injection problems.
The vulnerability, described here, exposed several IronPort components. Its Web framework would allow and authenticated remote user to execute arbitrary commands with elevated privileges.
“An authenticated but unprivileged attacker could exploit this vulnerability by sending a crafted URL to the affected system, or by convincing a valid user to click on a malicious URL. A successful exploit could allow an attacker with sufficient knowledge to take complete control of the affected device,” Cisco notes.
Cisco also notes that the IronPort spam quarantine and its management GUI are both vulnerable to denial-of-service attacks. The spam quarantine has an improper handling of TCP connection requests at high speed, while the GUI is vulnerable to DoS attacks on HTTP and HTTPS connections.
Cisco has patches available for affected software.
Facebook
Twitter
LinkedIn
Instagram
Call us today on 01283 576162 to talk directly to one of our server specialists
Who we are
Server Case UK are the UK's server case and components specialists, selling PC cases, server cases, 19" Rackmount cases, Backplane modules, mobile disk racks, externam disk boxes and power supplies. server systems and components with thousands of products available to purchase securely online.
UK's only authorised eCommerce reseller of server chassis to the general public & companies.
Latest News
NVIDIA Quadro RTX 4000 Is Here!
Posted on: 11th Dec 2018
Real time means real change....and real, affordable ray tracing! Meet today’s demanding professional workflows with GPU accelerated ray tracing, deep learning, and advanced shading. The NVIDIA® Quadro RTX™ 4000, powered by the NVIDIA Turing™ architecture and the NVID... [...] Read more
Latest Tweets
Latest Video
View more of our reviews, unboxing and installation videos on YouTube.
Business Links
Site Information