back to article Cisco fixes two critical make-me-root bugs on Identity Services Engine components

Cisco has dropped patches for a pair of critical vulnerabilities that could allow unauthenticated remote attackers to execute code on vulnerable systems. Tracked as CVE-2025-20281 and CVE-2025-20282, Cisco assigned them both maximum 10/10 severity ratings, although the former was reduced to 9.8 by the National Vulnerability …

  1. pc-fluesterer.info
    FAIL

    another two backdoors found?

    What a pity ...

    Why backdoor?

    "insufficient validation of user-supplied input" is either a severe malpractice - or a deliberate backdoor.

    "uploading a crafted file" means that the one who knows the key can trick the system.

    1. John_Ericsson

      Re: another two backdoors found?

      "Never attribute to malice that which is adequately explained by utter incompetence”

      1. pc-fluesterer.info

        Re: another two backdoors found?

        Incompetence? At market leader Cisco? You're kidding, aren't you.

        1. John_Ericsson

          Re: another two backdoors found?

          I don’t think market share comes into it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like