Vulnerabilities could lead to unauthorized control of devices
Cisco has issued a security advisory for its Network Building Mediator (NBM) and legacy Richards-Zeta Mediator products. The products allow different building systems to communicate with each other for facilities management.
Cisco acquired Richards-Zeta last year.
Multiple vulnerabilities affect the legacy Richards-Zeta Mediator 2500 product and Cisco Network Building Mediator NBM-2400 and NBM-4800 models. All Mediator Framework software releases prior to 3.1.1 are also affected.
The vulnerabilities exist in the areas of default credentials, privilege escalation, unauthorized information interception and unauthorized information access. Details can be found here. Successful exploitation of any of these vulnerabilities could result in a malicious user taking complete control over an affected device, the Cisco advisory states.
Cisco says it has released free software updates that address these vulnerabilities. Workarounds are also available that mitigate some of the vulnerabilities.
Cisco says the vulnerabilities were discovered during internal testing. The company is not aware of any public announcements or malicious use of the vulnerabilities described in the advisory.
More from Cisco Subnet:
Win great stuff from Cisco SubnetCisco Alert newsletter.Like RSS readers? Subscribe to the Cisco Subnet RSS feed
- NIST Gives Guidelines for Securing IPv6
- Cisco WiFi open to attack
- Hands On: What can Cisco do for and against network neutrality?
- Prototyping 101
- Venture Capital Investment Up, But Security Investment Is Down
- 2010 CCNP Lab Series – Overview
- ICND1 and ICND2 vs CCNA
- Win a CompTIA A+Study Guide
Like e-mail? Subscribe to the
Follow all Cisco Subnet bloggers on Twitter.Follow Jim Duffy on Twitter




