New Flaws Discovered in Cisco’s Network Operating System for Switches

From thehackernews.com

Cisco Network Operating System for Switches

Cisco has released software updates to address four security vulnerabilities in its software that could be weaponized by malicious actors to take control of affected systems.

The most critical of the flaws is CVE-2022-20650 (CVSS score: 8.8), which relates to a command injection flaw in the NX-API feature of Cisco NX-OS Software that stems from a lack of sufficient input validation of user-supplied data.

“An attacker could exploit this vulnerability by sending a crafted HTTP POST request to the NX-API of an affected device,” Cisco said. “A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system.”

Read more…