Skip to content
Brief Security & Trust ·

HKCERT flags multiple Cisco flaws, including remote code execution

The bulletin lists four Cisco advisories and sends readers to the vendor for affected versions.

In brief
  • HKCERT said on 8 October that Cisco products have several flaws, and a remote attacker could use some of them.
  • The bulletin gives no product list or versions, so teams must read Cisco's four linked advisories.

HKCERT said on 8 October that several security flaws were found in Cisco products. It said a remote attacker could use some of them to crash a system, get around security limits, read sensitive data, or run their own code. The bulletin links to four Cisco advisories and tells readers to check the vendor's site before installing software. The same day, HKCERT put out a separate bulletin on IBM WebSphere products. It said attackers could cause outages, gain higher access, read sensitive data or change data. It names WebSphere Application Server Liberty versions before 26.0.0.10.

The Cisco bulletin does not say which products or versions are affected. It gives no count of flaws, no severity ratings, and no word on whether attackers are using any of them. It also says only "some" of the flaws allow these outcomes, so not every flaw does every kind of harm. Three of the four linked advisory names include "nxos", but the bulletin does not explain what that means for readers. For IBM, the bulletin names only the Liberty versions and points to an IBM support page.

Teams that run Cisco equipment or IBM WebSphere cannot judge their exposure from these bulletins alone. They need the vendor advisories to see which versions are affected and what fixes exist.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: HKCERT, HKCERT.