MUST KNOW

Indian Govt Shares New Security Alert For These Users: All Details

22_06_2020-cyber_crime2_20421926

The new high risk security alert from the CERT-In concerns various Cisco products that are a core part of the businesses

The Indian Computer Emergency Response Team (CERT-In) which comes under the Ministry of Electronics & Information Technology, has issued an advisory over three serious vulnerabilities in networking giant Cisco products that could allow hackers to gain access, infiltrate into computer systems and steal data.

Read More: Are the spices being sold in Indian market safe? Lack of testing and poor law enforcement concerns

The vulnerabilities reported in Cisco Adaptive Security Appliance (ASA) software and Cisco Firepower Threat Defense (FTD) software could allow attackers to execute arbitrary commands and code on the underlying operating system with root-level privileges, device to reload unexpectedly, resulting in a denial of service (DoS), CERT-In said in its latest advisory.

The ‘Command Injection Vulnerability’ exists in the reported software due to the contents of a backup file being improperly sanitised at restore time.

Read More: Jaipur Leads AI Job Growth In India’s Tier 2 Cities, Report Reveals Top Roles

“An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device,” the cyber agency said.

Another ‘Denial of Service Vulnerability’ exists due to incomplete error checking when parsing an HTTP header.

Attackers could use this vulnerability by “sending a crafted HTTP request to a targeted web server on a device” and the successful exploitation could allow them to cause a “DoS condition when the device reloads”.

Read More: What is the PPI Charge on UPI Payments? Who Does it Affect and What You Need to Know?

The third, ‘Code Execution Vulnerability’ exists due to improper validation of a file when it is read from system flash memory.

According to the cyber agency, an attacker could exploit this vulnerability by copying a “crafted file to the disk0: file system of an affected device”.

In addition, CERT-In advised people to apply appropriate updates as released by Cisco.

Source :
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Most Popular

To Top