Saturday, March 25, 2023
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory
  • Login
  • Register
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
No Result
View All Result
Cloud7 News
No Result
View All Result

Home > Cybersecurity > Cisco fixes command injection vulnerability

Cisco fixes command injection vulnerability

Cisco has acknowledged that a high-severity bug that affects its IOx application hosting environment has been patched.


Ezgi Koc Ezgi Koc
February 6, 2023
2 min read
Cisco fixes command injection vulnerability
  • A high-severity problem that affects Cisco’s IOx application hosting environment has been acknowledged and addressed by the company.
  • If a Cisco device has the Cisco IOx feature activated and does not support native Docker, it is vulnerable to this exploit if it is running Cisco IOS XE software.
  • To fix the flaws, Cisco has made free software updates available. Additionally, Cisco advises users to update to a corrected software release.

Cisco IOS XE is a software-based, modular operating system for Cisco hardware platforms. It includes the Cisco NX-OS Software and the Cisco IOS Software. Cisco has confirmed that it has fixed a high-severity flaw that is impacting its IOx application hosting environment. The vulnerability could allow someone to exploit it by deploying and activating an application in the Cisco IOx application hosting environment. The vulnerability was tracked as CVE-2023-20076.

Affected Products

This vulnerability affects Cisco devices that are running Cisco IOS XE Software if they have the Cisco IOx feature enabled and they do not support native docker. his vulnerability also affects the following Cisco products, which do not support native docker, if they are running a vulnerable software release and have the Cisco IOx feature enabled:

  • 800 Series Industrial ISRs.
  • CGR1000 Compute Modules.
  • IC3000 Industrial Compute Gateways (releases 1.2.1 and later runs native docker).
  • IR510 WPAN Industrial Routers.

Products Confirmed Not Vulnerable

  • Catalyst 9000 Series Switches (native docker is supported in all releases)
  • Cisco Catalyst 9100 Family of Access Points (COS-AP)
  • IOS XR Software
  • Meraki products
  • NX-OS Software (native docker is supported in all releases)

Sam Quinn and Kasimir Schulz of the Trellix Advanced Research Center found an issue with how tar archives are extracted which could allow an attacker to write on the underlying operating system as root. Cisco confirms that an issue exists with an unsupported compression algorithm, but says that there is no immediate way to exploit it. In the case that a future platform does not support the compression algorithm, Cisco has found a solution to this problem.

Cisco has released free software updates that address the vulnerabilities. Cisco also recommends that customers upgrade to a fixed software release. The first release that includes the fix for this vulnerability is listed in the right column.

See more Cybersecurity News

A comprehensive guide to understanding Cybersecurity: What is Cybersecurity?


Tags: Cisco Systems
Ezgi Koc

Ezgi Koc

Ezgi Koc is an editor at Cloud7. She graduated from Ege University with a bachelor's degree in English Language and Literature. She has always had great interest in technology, both hardware and software, since her childhood and decided to pursue a career that would enable her to broaden her horizons in this field. She is very passionate about video games as a Twitch affiliate and streams games in her free time.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Next Post
VMWare ESXi is now available on Google Cloud

VMWare ESXi is now available on Google Cloud

Related News

7 best practices and tools to use for Linux security

7 best practices and tools to use for Linux security

March 24, 2023 5:00 pm
CISA aims to identify vulnerabilities that attract ransomware

CISA aims to identify vulnerabilities that attract ransomware

March 22, 2023 2:10 pm
7 best cybersecurity schools

7 best cybersecurity schools

March 21, 2023 9:00 pm
Akamai researchers warn about the new HinataBot botnet

Akamai researchers warn about the new HinataBot botnet

March 20, 2023 6:10 pm
Get free daily newsletters from Cloud7 News Get the Cloud7 Newsletter
Select list(s):

Check your inbox or spam folder to confirm your subscription.

By subscribing, you agree to our
Copyright Policy and Privacy Policy

Get the free newsletter

Subscribe to receive the latest IT business updates straight to your inbox.

Select list(s):

Check your inbox or spam folder to confirm your subscription.

Recent News

  • Podman Desktop – Containers & Kubernetes (Podcast #15 w/ Markus Eisele)
  • What is a Daemon in Linux?
  • 7 best practices and tools to use for Linux security
  • Photopea review: The best free Photoshop alternative for Linux
  • CloudFest 2023 is completed

Cloud7 News
Cloud7 is a news source that publishes the latest news, reviews, comparisons, opinions, and exclusive interviews to help tech users of high-experience levels in the IT industry.

EXPLORE

  • Web Hosting
  • Cloud Computing
  • Data Center
  • Cybersecurity
  • Linux
  • Network/Internet
  • Software
  • Hardware
  • Artificial Intelligence
  • How-Tos
  • Troubleshooting

RESOURCES

  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

Get the Cloud7 Newsletter

Get FREE daily newsletters from Cloud7 delivering the latest news and reviews.

  • About Us
  • Privacy & Policy
  • Copyright Policy
  • Contact

© 2023, Cloud7 News. All rights reserved.

No Result
View All Result
  • Cloud Computing
  • Web Hosting
  • Data Center
  • Linux
  • Cybersecurity
  • More
    • Software
    • Network/Internet
    • Hardware
    • Artificial Intelligence
    • Windows
    • Policy/Legislation
    • Blockchain
    • Troubleshooting
    • How-Tos
    • Articles
  • Events
  • Interviews
  • Jobs
  • Opinion
  • Whitepapers
  • Podcasts
  • Web Hosting Directory

© 2023, Cloud7 News. All rights reserved.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.