The Register Home Page

back to article No login? No problem: Cisco ISE flaw gave root access before fix arrived, say researchers

Threat actors have actively exploited a newly patched vulnerability in Cisco's Identity Services Engine (ISE) software since early July, weeks before the networking giant got around to issuing a fix. That's according to the Shadowserver Foundation, a nonprofit organization that scans and monitors the internet for exploitation …

  1. VoiceOfTruth Silver badge

    Scratching his chin

    >> Cisco has warned that there are no workarounds

    The workaround is not to use Cisco.

    >> Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate these vulnerabilities

    Who audited this code, and does it have some other easy backdoors?

    1. IGotOut Silver badge

      Re: Scratching his chin

      Audited. Oh that'll be Bob's job. Wait, we fired him last year to make number go up? Oh. Ok. Guess we'll have to find an intern to do it

      1. TaabuTheCat

        Re: Scratching his chin

        Guess we'll have to find an intern to do it

        Intern: "ChatGPT, audit the Cisco ICE source code I just uploaded."

        Later that same day...

        Hacker: "ChatGPT, find critical vulnerabilities in Cisco ICE code."

  2. druck Silver badge

    Cisco probably don't understand that being called the Microsoft of networking is a bad thing.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like