Cisco has released critical security updates for its Crosswork platforms and Secure Workload software to address multiple high-severity vulnerabilities discovered during a comprehensive internal security review.
Key Points
- Cisco patched four critical vulnerabilities in Crosswork Data Gateway, Network Controller, and Planning, all affecting version 7.2.1 and earlier.
- Three of the Crosswork flaws received a maximum CVSS score of 10.0, including issues related to SQL injection and missing authentication.
- Five vulnerabilities in Cisco Secure Workload were remediated, with fixes now available for versions 3.10 and 4.0.
- The Secure Workload patches address severe security risks, including command injection, authentication bypass, and buffer overflow vulnerabilities.
- Cisco confirmed these flaws were identified through internal testing and are not currently known to be exploited in the wild.