For the second time in a week, Cisco has issued a security alert, this time for its CiscoWorks Internetwork Performance Monitor product. According to its security advisory, Cisco says CiscoWorks Internetwork Performance Monitor (IPM) version 2.6 for Sun Solaris and Microsoft Windows contains a hole that could allow remote, unauthenticated users to executive arbitrary commands. Cisco had made available a fix for the problem, which can be accessed from the security advisory.
The advisory adds that: “Successful exploitation of the vulnerability may result in the ability to execute arbitrary commands with the non-privileged casuser user account on Solaris systems and with full administrative SYSTEM privileges on Windows systems.”
On Wednesday, Cisco patched two flaws in its Secure Access Control Server.
More from Cisco Subnet: * Scientific-Atlanta officially loses its name – sign of things to come for Linksys? * Nortel enterprise director: Cisco insults users’ intelligence * Do you have an architecture review board? * Cisco, Patent Troll Tracker sued for defamation * Salary survey says CCIE pay is slipping * Understanding MPLS label distribution * Why an economic recession could leave companies wide open to cyber attacks * Cisco Ferrari or Nortel lawn mower, which one will customers choose to ride? * Security wireless networks: Securing wireless comms over the air Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more. Recent Cisconet blog entries 20 useful sites for Cisco networking professionals Network World’s IT Buyer’s Guide: Cisco products Subscribe to Network World’s Cisco Alert, which includes a weekly digest of all Cisco Subnet items




