Cisco Systems has warned of serious vulnerabilities in a device that connects a building s ventilation, lighting, security, and energy supply systems so they can be controlled by IT workers remotely. The networking giant urged users of the Cisco NetworkBuilding Mediator products to patch the vulnerabilities, which among other things allow adversaries to obtain administrative passwords. Cisco today released patches for two products, including one for a vulnerability rated high criticality in Cisco IOS XR for Cisco Network Convergence System series routers.
Source: https://threatpost.com/cisco-warns-vulns-building-systems-052610/74023/