Blog | G5 Cyber Security

Critical Vulnerability in Cisco Elastic Services Controller

The Cisco Elastic Services Controller is a virtual network functions manager, which enables businesses to automate the deployment and monitoring of functions running on their virtual environments. A successful exploit of this vulnerability let an attacker execute arbitrary actions through the REST API with administrative privileges on an affected system. The vulnerability was found during internal security testing and is fixed in Cisco Elastic Service Controller Release 4.5, According to the Cisco report. The following example shows the output of the command for a machine that has the REST. API service enabled on port 8443.”]

Source: https://gbhackers.com/critical-vulnerability-elastic-services/

Exit mobile version