Connect with us

    Hi, what are you looking for?

    Tech

    Assess Exposure to Multiple Vulnerabilities in Cisco Products to find Solutions, NCC-CSIRT Advises Users

    NCC

    The Nigerian Communications Commission’s Computer Security Incident Response Team (NCC-CSIRT) has issued an advisory for users to frequently review alerts for Cisco products to assess their exposure and find a comprehensive update solution.

    The advisory, which also recommended using the appropriate software updates that are accessible from the vendor website, followed the identification of multiple vulnerabilities in Cisco Products, especially the Cisco AnyConnect Secure Mobility Client for Windows, which enables employees to access company servers from anywhere without compromising security.

    The two vulnerabilities made it possible for a remote attacker exploit to trigger remote code execution and data manipulation on the targeted system.

    Read Also: NCC to Accelerate Deployment of Emerging Technologies

    According to the advisory, “The weaknesses in the product include uncontrolled search path and Dynamic Link Library (DLL) hijacking vulnerabilities. The uncontrolled search path vulnerability results from incorrect handling of directory paths. A directory path is a string of characters used to uniquely identify a location in a folder structure.

    “This flaw could be exploited by an attacker by generating a malicious file and copying it to a system directory (folder). An exploit could enable the attacker to copy malicious files with system-level privileges to any location. The attacker needs legitimate Windows system credentials to exploit this vulnerability.

    “Moreover, to exploit the DLL hijacking vulnerability, the attacker would also need to have valid credentials on the Windows system. The vulnerability was caused by the device’s inadequate run-time resource validation. By sending the AnyConnect process a specially designed IPC message, an attacker might take advantage of this vulnerability.”

    The advisory rated the vulnerability high in impact and probability.

    The CSIRT is the telecom sector’s cyber security incidence centre set up by the NCC to focus on incidents in the telecom sector and as they may affect telecom consumers and citizens at large.

    The CSIRT also works collaboratively with ngCERT, established by the Federal Government to reduce the volume of future computer risk incidents by preparing, protecting, and securing Nigerian cyberspace to forestall attacks, and problems or related events.

     

    Loading

    Spread the love
    Click to comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    ad

    You May Also Like

    E-Financial

    Wema Bank has introduced SAW, a new AI voice assistant integrated into the ALAT 2.0 app, allowing customers to manage finances through natural voice...

    E-Financial

    Kuda Microfinance Bankk has unveiled the 2025 edition of “My Year on Kuda,” its annual recap providing customers with personalised insights into their spending,...

    News

    A federal judge in the United States has ordered Aimee Bock, the 44-year-old founder of Minnesota-based Feeding Our Future nonprofit, to surrender her Porsche...

    News

    Aig-Imoukhuede Foundation has announced its 2025 achievements, marking a year of accelerated impact, systemic reforms and innovation in public leadership and service delivery across...