Thursday, November 8, 2018

Vendor Blunder - Cisco “inadvertently” shipped in-house exploit code that was used in security tests of scripts as part of its TelePresence Video Communication Server and Expressway Series software.



The code was used internally by Cisco in validation scripts to be included in shipping software images – it was used to ensure that Cisco’s software is protected against known exploits. However, there was a failure in the final QA validation step of the software, and as a result someone from Cisco forgot to remove the code before release

https://threatpost.com/cisco-accidentally-released-dirty-cow-exploit-code-in-software/138888/

No comments:

Post a Comment