Cisco posted 17 security warnings about authentication vulnerabilities in its Unified Computing System Credit: PeopleImages / Getty Images Cisco has posted a package of 17 critical security warnings about authentication vulnerabilities in its Unified Computing System that could let attackers break into systems or cause denial of service troubles. Specifically the problems are with Cisco’s UCS Director and Express which let customers build private-cloud systems and support automated provisioning processes and orchestration to optimize and simplify delivery of data-center resources, the company said. Most of the problems center around a weakness in the REST API – which is employed in a variety of Web-based applications – in the affected Cisco products. Cisco said the vulnerabilities have a 9.8 out of 10 score on the Common Vulnerability Scoring System. Some of he problems: A vulnerability in the REST API of Cisco UCS Director and UCS Director Express for Big Data could let an unauthenticated, remote attacker bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to insufficient access control validation. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A vulnerability in the REST API of Cisco UCS Director and UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system. The vulnerability is due to improper input validation. An attacker could exploit this weakness by crafting a malicious file and sending it to the REST API, Cisco stated. A vulnerability in the REST API of Cisco UCS Director and UCS Director Express for Big Data could let an unauthenticated, remote attacker bypass authentication and execute API calls on an affected device. The vulnerability is due to insufficient access control validation. A successful exploit could allow the attacker to interact with the REST API and cause a potential Denial of Service (DoS) condition on the affected device, Cisco said. Cisco said it has released free software updates that address the vulnerabilities and has fixed the vulnerabilities in UCS Director Release 6.7.4.0 and UCS Director Express for Big Data Release 3.7.4.0. Steven Seeley (mr_me) of Source Incite worked with Trend Micro Zero Day Initiative to divulge the problems, which have not been exploited, the company said. In addition to the UCS products, Cisco issued two other critical security warnings this week with its IP Phones. First, a vulnerability in the web server for Cisco IP Phones could let an unauthenticated, remote attacker execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition, Cisco stated. This vulnerability affects the following Cisco products if they have web access enabled and are running a firmware release earlier than the first fixed release for that device: IP Phone 7811, 7821, 7841, and 7861 Desktop Phones IP Phone 8811, 8841, 8845, 8851, 8861, and 8865 Desktop Phones Unified IP Conference Phone 8831 Wireless IP Phone 8821 and 8821-EX The other IP Phone issue involved the web application for Cisco IP Phones that could let an attacker send a crafted HTTP request to the web server of a targeted device. A successful exploit could let the attacker remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a DoS condition. The vulnerability exists because the affected software fails to check the bounds of input data, Cisco stated. Cisco said it has released free software updates to fix the problems. Related content news Broadcom to lay off over 1,200 VMware employees as deal closes The closing of VMware’s $69 billion acquisition by Broadcom will lead to layoffs, with 1,267 VMware workers set to lose their jobs at the start of the new year. By Jon Gold Dec 01, 2023 3 mins Technology Industry Technology Industry Markets news analysis Cisco joins $10M funding round for Aviz Networks' enterprise SONiC drive Investment news follows a partnership between the vendors aimed at delivering an enterprise-grade SONiC offering for customers interested in the open-source network operating system. By Michael Cooney Dec 01, 2023 3 mins Network Management Software Industry Networking news Cisco CCNA and AWS cloud networking rank among highest paying IT certifications Cloud expertise and security know-how remain critical in building today’s networks, and these skills pay top dollar, according to Skillsoft’s annual ranking of the most valuable IT certifications. Demand for talent continues to outweigh s By Denise Dubie Nov 30, 2023 7 mins Certifications Network Security Networking news Mainframe modernization gets a boost from Kyndryl, AWS collaboration Kyndryl and AWS have expanded their partnership to help enterprise customers simplify and accelerate their mainframe modernization initiatives. By Michael Cooney Nov 30, 2023 4 mins Mainframes Cloud Computing Data Center Podcasts Videos Resources Events NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe