Security hole in Cisco Elastic Services Controller gets a 10 out of 10 vulnerability rating Credit: Zapp2Photo / Getty Images Cisco has released a patch for a critical vulnerability in software used to control large virtual environments. The weakness gets a 10 out of 10 severity score and is found in Cisco’s Elastic Services Controller (ESC), which the company describes as offering a single point of control to manage all aspects of Virtual Network Functions and offers capabilities such as VM and service monitoring, auto-recovery and dynamic scaling. With ESC users control the lifecycle all virtualized resources, whether using Cisco or third-party VNFs, Cisco stated. The vulnerability in this case lies in the REST API of ESC and could let an unauthenticated remote attacker to bypass authentication on the REST API and execute arbitrary actions through with administrative privileges on an affected system. The vulnerability is due to improper validation of API requests, Cisco wrote in its advisory. This vulnerability affects Cisco ESC running Software Release 4.1, 4.2, 4.3 or 4.4 when the REST API is enabled. The REST API is not enabled by default, Cisco noted. The vulnerability is fixed in Cisco Elastic Services Controller Release 4.5. Cisco said the susceptibility was found during internal security testing and the company is not aware of any public announcements or malicious use of the vulnerability. Cisco has released free software updates that address this vulnerability and suggests going here for the fix. This announcement was Cisco’s second “critical” patch this month. Last week Cisco said a vulnerability in its Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode data center switch that could let an attacker secretly access system resources. That patch was part of some 40 security advisories issued last week. Related content news analysis Cisco, AWS strengthen ties between cloud-management products Combining insights from Cisco ThousandEyes and AWS into a single view can dramatically reduce problem identification and resolution time, the vendors say. By Michael Cooney Nov 28, 2023 4 mins Network Management Software Network Management Software Networking opinion Is anything useful happening in network management? Enterprises see the potential for AI to benefit network management, but progress so far is limited by AI’s ability to work with company-specific network data and the range of devices that AI can see. By Tom Nolle Nov 28, 2023 7 mins Generative AI Network Management Software brandpost Sponsored by HPE Aruba Networking SASE, security, and the future of enterprise networks By Adam Foss, VicePresident Pre-sales Consulting, HPE Aruba Networking Nov 28, 2023 4 mins SASE news AWS launches Cost Optimization Hub to help curb cloud expenses At its ongoing re:Invent 2023 conference, the cloud service provider introduced several new and free updates that are expected to help enterprises optimize their AWS costs. By Anirban Ghoshal Nov 28, 2023 3 mins Amazon re:Invent Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe