Usa science news

  • Science
  • Usa News

Cisco tells customers to upgrade VPN routers or risk attack

  • Home
  • 2022
  • June
  • 20
  • Cisco tells customers to upgrade VPN routers or risk attack
June 20, 2022Usa science newsNo Comments

Share your thoughts on Cybersecurity and get a free copy of the Hacker’s Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

End of life

These models, however, have reached end-of-life status and as such will not be patched.

A small caveat is that the web-based remote management interface on WAN connections needs to be enabled for the flaw to be exploitable, and by default, it’s not. Still, many exposed devices can be found with a quick Shodan search.

To double-check if your routers have this feature enabled, log into the web-based management interface, and head over to Basic Settings – Remote Management, and uncheck the box. Furthermore, this is the only way to mitigate the threat, and users are advised to do that before moving on to newer models. Cisco was said to be “actively supporting” models RV132W, RV160, and RV160W.

Read more

> Cisco will not patch serious security hole in its old VPN routers

> These critical Cisco bugs need patching immediately

> Cisco routers suffer from multiple maximum severity security bugs

RV160, together with RV260, RV340, and RV345, recently received a patch for five vulnerabilities with a 10/10 severity rating. Among the possibilities for malicious actors exploiting these flaws are arbitrary code and command execution, elevation of privileges, running unsigned software, circumventing authentication, and assimilating the devices into a botnet for Distributed Denial of Service (

Cisco has advised customers to trade in old Small Business RV VPN routers for newer models, as the old ones have high-severity vulnerabilities that it won’t be patching.

As reported by BleepingComputer, the company recently discovered a vulnerability revolving around insufficient user input validation of incoming HPPT packets. By sending a “specially crafted request” to the web-based management interface of these devices, an attacker could end up with root-level privileges. Essentially, they’d be getting free access to the endpoint.

Tracked as CVE-2022-20825, the flaw has a severity score of 9.8, so it’s pretty dangerous. It was found in four models: the RV110W Wireless-N VPN Firewall, the RV130 VPN Router, the RV130W Wireless-N Multifunction VPN Router, and the RV215W Wireless-N VPN Router.

Share your thoughts on Cybersecurity and get a free copy of the Hacker’s Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the

Source:: TechRadar – All the latest technology news

      


NASA Chooses Spacex To Launch A Self Propelled Space Station To The Moon
Science

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • The James Webb Space Telescope is ready for SCIENCE. Here’s what that means
  • Elden Ring devs could be working on a game we’ve been waiting on for 10 years
  • Here’s Google’s letter saying employees can relocate to states with abortion rights
  • New study explains what may have triggered ice age
  • Federal appeals court pauses FDA ban on Juul’s e-cigarettes
  • Why does everyone seem to have food intolerances these days?
  • Hearing and vision issues linked to cognitive impairment in older people
  • Your BMI is linked to death and longer ICU stay for COVID
  • Why women’s heart attacks are often missed
  • Type 2 diabetes: short-term low-carb diet linked to remission – but only if weight is lost
  • PlayStation studios, major publishers break silence on abortion rights
  • Mars probe running Windows 98 receives software update after two decades
  • Meta wants the virtual landscape to sound like real life
  • Apple’s AR/VR headset will arrive in January 2023, analyst projects
  • T-Mobile is selling your app usage data to advertisers — here’s how to opt out
  • LG’s unique new Dolby Atmos soundbar is now on sale
  • The latest Windows updates could fix your broken VPN
  • Samsung’s monstrous 55-inch Odyssey Ark monitor could go on sale in August
  • NASA’s Psyche mission launch on hold indefinitely pending reevaluation
  • Latest AirPods Pro 2 rumors are all about that case
  • Samsung Galaxy Z Flip 4 could be the most colorful and customizable phone yet
  • Microsoft prepares to forget about Windows 8.1 with end of support notifications
  • Apple’s AR / VR headset could release in January, analyst predicts
  • Drunk or drowsy? This cabin controller from Hyundai wouldn’t let you drive
  • Spotify is bringing a great desktop feature to phones at last
  • 6 great Samsung Galaxy S22 features you can find on Samsung’s cheaper phones
  • His shortness of breath signaled a deeper, underlying issue
  • Scientists find particle accelerator region inside a solar flare
  • Should you take aspirin to prevent heart attacks?
  • A how-to guide to the latest COVID therapies
  • Acclaimed strategy game Into the Breach comes to mobile via Netflix
  • Meta is saving millions of dollars thanks to this clever memory hack
  • Tesla partners with California utility on virtual power plant
  • TikTok TV finds a new home on VIZIO’s affordable TVs – with a small catch
  • Open source security is rapidly becoming a major concern
  • Keanu Reeves apparently likes NFTs now
  • In Russia, Western planes are falling apart
  • Solana is making a crypto phone with help from former Essential engineers
  • Meta reportedly plans to shut down CrowdTangle, its tool that tracks popular social media posts
  • TikTok comes to Vizio TVs
Powered by WordPress | Theme: Exoplanet by UXL Themes