Cisco Patched High-Severity Vulnerabilities in Crosswork and Secure Workload
Cisco has released security updates for its Crosswork and Secure Workload products to address nine vulnerabilities, including five with maximum severity. The flaws involve SQL injection, missing authentication, file-control weaknesses, improper access control, and improper authentication.
The affected products include Cisco Crosswork Data Gateway, Network Controller, Planning, Workflow Manager, and Cisco Secure Workload On-premises 3.10 and earlier versions, as well as version 4.0. The company says it is not aware of public announcements or malicious exploitation of these vulnerabilities.
Cisco recommends that affected deployments be upgraded to the fixed releases as soon as possible, as there are no workarounds available. Affected customers should also restrict management interfaces to trusted administrative networks while upgrades are planned and review logs for unusual management activity.