Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs

Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs

Roundup It's once again time to catch up on the latest happenings from the world of infosec.


Cisco emits critical fix in latest patch bundle


We have a bunch of new security patches from Switchzilla, including one for a critical hole in its call-center software.


CVE-2020-3280 is a remote-code-execution vulnerability in the Java remote management interface for Unified Contact Center Express.


An unauthenticated, remote attacker able to exploit the flaw by supplying a malformed Java object (this is possible through various user input fields) can gain get root control over the management system. Admins are being advised to update Unified CCX as soon as possible.


< ..

Support the originator by clicking the read the rest link below.