Cisco Patches Critical Vulnerabilities Across Multiple Products
Cisco has released patches for 15 vulnerabilities across its products, including critical and high-severity flaws in Crosswork and Secure Workload.
The company fixed four critical-severity CVEs in Crosswork version 7.2.1-SP, three of which have a maximum severity rating (CVSS score of 10/10) and the fourth with a near-max severity (CVSS score of 9.9/10).
Cisco says each CVE groups multiple issues under the same underlying vulnerability class, including SQL injection, missing authentication, external control of file system, and insufficient protection of credentials.
The vulnerabilities in Crosswork could potentially allow attackers to mount remote code execution (RCE), authentication bypass, path traversal, and file overwrite/deletion attacks.