Max-Critical Cisco Bug Enables Command-Injection Attacks
ID: 2cdb731e-e298-54f8-be41-318c6ca85c37
STIX ID: report--2cdb731e-e298-54f8-be41-318c6ca85c37
Feed Name: Dark Reading
Threat Score
Cisco has disclosed a critical (CVSS 10) command-injection vulnerability (CVE-2024-20418) in its Unified industrial Wireless Software for Ultra-Reliable Wireless Backhaul (URWB) access points that allows unauthenticated HTTP requests to the device web management interface to execute arbitrary commands as root; the flaw affects Catalyst IW9165D, IW9165E, and IW9167E when URWB mode is enabled, Cisco provided a patch and reports no known public exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
