Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Cisco Bug Ranks as One of the Worst

Cisco Bug Ranks as One of the Worst

A new exploit is making the rounds in the security environment, and this time, it affects virtual private networks. According to Cisco, the flaw affects its Adaptive Security Appliance (ASA) tool, and it should be patched as quickly as possible. If you don’t do so, your organization could be subject to remote code exploitation as a result of this vulnerability.

Cisco has showcased that the VPN bug can essentially allow hackers to infiltrate their security devices using the ASA operating system. The vulnerability is found in the Secure Sockets Layer (SSL) and can, according to Cisco, “allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code.” What does this mean in plain English? In theory, an attacker could take complete and total control over a system (a considerable threat for any organization, especially considering the ramifications from a physical security standpoint). This vulnerability is so dangerous that it has earned a 10-out-of-10 on the Common Vulnerability Score System, taking its place among the upper echelon of major vulnerabilities.

While the vulnerability is only allowed if WebVPN is enabled, it’s still a major threat that you don’t want to overlook. According to ZDNet, here are some of the devices that are affected by this vulnerability:

  • 3000 Series Industrial Security Appliance (ISA)
  • ASA 5500 Series Adaptive Security Appliances
  • ASA 5500-X Series Next-Generation Firewalls
  • ASA Services Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
  • ASA 1000V Cloud Firewall
  • Adaptive Security Virtual Appliance (ASAv)
  • Firepower 2100 Series Security Appliance
  • Firepower 4110 Security Appliance
  • Firepower 9300 ASA Security Module
  • Firepower Threat Defense Software (FTD).

At its time of discovery, the bug was not being exploited in the wild, but Cisco has been made aware of attempts to leverage of the vulnerability. Since the announcement, the vulnerability has been spotted in the wild, and the initial patch that Cisco implemented to combat this vulnerability proved to insufficient, as there were additional features and attack vectors that were not identified until later.

Cisco has released an updated patch for this vulnerability, so you need to implement it if you don’t want to take a needless risk, and endanger your network and data. It’s a good rule of thumb to never let known vulnerabilities linger too long, as you could be placing your business in harm’s way.

It’s incredibly important that your business be mindful of not just these vulnerabilities, but all vulnerabilities found in critical business software and hardware. This Cisco bug isn’t the first software vulnerability to be found, and it certainly won’t be the last. Hackers are always working to undermine the efforts of developers who are trying to keep their software as secure as possible. It’s up to you to ensure your organization isn’t exposing itself to threats by neglecting patches and security updates.

Total Tech Care can help your organization ensure that patches and updates are applied as needed. We can do this remotely in most cases, without the need for an on-site visit. It’s a great way to get more value out of your business’ technology without sacrificing security. To learn more about how you can make technology work for you, reach out to us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 21 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Workplace Tips Backup Innovation Data User Tips Computer Mobile Devices Hardware IT Services Android Disaster Recovery VoIP communications Business Continuity IT Support Smartphones Communication Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Managed IT Services Upgrade Windows Phishing Data Backup Outsourced IT Ransomware Windows 10 Office Server Save Money Data Recovery Cloud Computing Passwords Windows 10 Gadgets Tech Term Saving Money Holiday Social Media Chrome Virtualization Automation Microsoft Office Managed IT Services Managed Service Artificial Intelligence Facebook Operating System Cybercrime Computers BYOD Wi-Fi Mobile Device Management Networking IT Support Hacking Health Internet of Things Covid-19 Alert Spam Office 365 Telephone Systems Managed Service Provider Information Technology Remote Information Bandwidth Social Engineering Mobility Router Employer-Employee Relationship Recovery BDR Remote Monitoring Application Password Money Data Breach App History Encryption Big Data Applications Human Resources Law Enforcement Mobile Computing Mobile Office Managed IT Data Storage Patch Management Apps Office Tips Training VPN Blockchain Paperless Office Government How To Remote Computing Private Cloud Voice over Internet Protocol Website HaaS Budget Bring Your Own Device Vulnerability Data Management Windows 7 Work/Life Balance Word Servers Wireless Google Drive Gmail Data Security Settings Avoiding Downtime Flexibility Two-factor Authentication Marketing WiFi IT solutions Mouse Infrastructure Entertainment Save Time USB User Error Conferencing Meetings Employee/Employer Relationship Cleaning Scam RMM Data Protection Risk Management Hacker End of Support Vendor Management Education Physical Security The Internet of Things Lithium-ion battery Safety Sports HIPAA Redundancy Keyboard Telephone System Staff Software as a Service Firewall Machine Learning Virtual Reality Connectivity Remote Work Vendor Apple Managed Services Display Social Processor Data storage Augmented Reality Automobile Hard Drive Fraud Business Intelligence IT Consultant Wearable Technology Retail Remote Worker Hard Drives Computing Infrastructure Worker Going Green Instant Messaging Audit Robot IT Management Cryptocurrency Excel Computing Humor Botnet Biometrics Virtual Desktop IT Plan Battery Shadow IT Comparison Legal Unsupported Software CES Digital Signage DDoS Internet Exlporer Charger SharePoint Business Technology Content Management Access Control Compliance PDF Computer Care Procurement OneNote Customer Service Virtual Assistant Workplace Strategy Current Events Net Neutrality Proactive IT Virus Telephony Environment Authentication Samsung Help Desk Fax Server Printing Best Practice Unified Threat Management YouTube Computer Accessories Value Black Market Update SaaS Spam Blocking Electronic Medical Records Managed Services Provider Document Management Google Docs Database Wireless Technology Printer Network Congestion Hiring/Firing Identity Theft Solid State Drive How to Bluetooth Remote Workers Downtime eWaste Tip of the week MSP Email Best Practices Tablets webinar Accountants IT Assessment Emergency Files Manufacturing Chromecast Printer Server Professional Services Microchip Entrepreneur Public Cloud Thought Leadership Employer Employee Relationship Credit Cards Computer Tips Assessment Password Manager Managed IT Service Security Cameras Password Management Shortcut Windows Server 2008 Virtual CIO OneDrive Multi-Factor Security Colocation Biometric Security Uninterrupted Power Supply Tools Search Engine Cost Management Twitter Peripheral NIST Digital Security Cameras Television Business Mangement Using Data Monitor Social Networking Smart Tech Copiers Trending 5G Amazon Addiction Quick Tip Ergonomics Public Computer Recycling Reputation Smartwatch Streaming Media Running Cable Tech Support Regulations Wiring Memory Practices Content Development Transportation OLED Rootkit Amazon Web Services Techology Virtual Machine Laptop Computer Fan Cache PCI DSS Safe Mode 2FA Criminal Fiber Optics Customers Employee GDPR Workers Hosted Computing Audiobook Messaging Benefits Consultant Cabling Online Shopping Hypervisor Touchpad Analytics FENG Wireless Internet Policy File Sharing Dark mode Science IBM Trend Micro Flash Camera Inventory Politics SMS Smart Technology Specifications Advertising Best Available Default App Evernote WIndows 7 Saving Time Wire Procedure Customer Relationship Management Software Tips dark theme Supercomputer Shopping Travel Google Search Notifications Distributed Denial of Service Sync Printers Analyitcs Emails AI Millennials IT Infrastructure Wireless Charging Bing Programming Smart Office FinTech Social Network Relocation Virtual Private Network Netflix Two Factor Authentication Workforce Investment Cables Video Games User Employee/Employer Relationships PowerPoint Windows Media Player Antivirus Root Cause Analysis Employees HBO Windows 365 Windows 8 Knowledge Worker Commute Music ISP IT service Skype Project Management Nanotechnology Experience Video Conferencing Telecommuting ROI Cortana Scalability Managing Stress Bitcoin Shortcuts Data loss Sales Outlook Point of Sale Tablet Leadership Digital Signature Business Owner Personal Troubleshooting Cryptomining NarrowBand Cameras Domains Start Menu Warranty Supply Chain Management Monitoring Loyalty Google Apps Search Batteries Screen Mirroring HVAC Maintenance Frequently Asked Questions Windows 8.1 Analysis Digitize Books iPhone IaaS Windows Server 2008 R2 Mobile Administrator Bloatware Windows 10s Devices Customer relationships Cast Enterprise Content Management

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code