Get a Pentest and security assessment of your IT network.

Cyber Security

Cisco Fixes Critical Vulnerability in Elastic Services Controller

An unauthenticated, remote attacker could exploit the flaw on deployments that have REST API enabled. The security issue is now identified as CVE-2019-1867 and its cause is improper validation of API requests. An attacker leveraging it successfully can bypass authentication on the REST API and run arbitrary actions with administrative privileges. The vulnerability was found internally during security testing and there is no evidence that the glitch has been exploited in the wild. The company rolled out patches for each of its major versions of Software Release 4.1, 4.2,. 4.3, or 4.4.

Source: https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-vulnerability-in-elastic-services-controller/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security