<?xml version="1.0" encoding="UTF-8"?>
<rss  version="2.0"> 
   <channel>
  <title>Cisco Security Advisories</title>
  <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
  <description>Cisco Security Advisories (the 40 most recent advisories)</description>
  <language>en-us</language>
  <copyright>&#xA9; 1992-2008 Cisco Systems, Inc. All rights reserved.</copyright>
  <managingEditor>news-at-cisco-rss@cisco.com</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com</webMaster>
  <pubDate>Fri, 02 May 2008 12:01:02 PST</pubDate>
  <lastBuildDate>Fri, 25 Apr 2008 11:00:00 PST</lastBuildDate>
  <category>Security Advisories</category>
  <generator>News@Cisco RSS Script</generator>
  <docs>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</docs>
  <ttl>60</ttl>
  <image>
    <title>News@Cisco</title>
    <url>http://newsroom.cisco.com/images/mobile_newsAtCisco.png</url>
    <link>http://www.cisco.com/en/US/products/products_security_advisories_listing.html</link>
    <width>107</width>
    <height>70</height>
  </image>
  <textInput>
    <title>Search Cisco</title>
    <description></description>
    <name>searchPhrase</name>
    <link>http://www.cisco.com/pcgi-bin/search/search.pl</link>
  </textInput>
  
     <item>
    <title>Cisco IOS User Datagram Protocol Delivery Issue For IPv4/IPv6 Dual-stack Routers</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008096986d.shtml</link>
    <description>A device running Cisco IOS software that has Internet Protocol version 6 (IPv6) enabled may be subject to a denial of service (DoS) attack. For the device to be affected by this vulnerability the device also has to have certain Internet Protocol version 4 (IPv4) User Datagram Protocol (UDP) services enabled. To exploit this vulnerability an offending IPv6 packet must be targeted to the device. Packets that are routed throughout the router can not trigger this vulnerability. Successful exploitation will prevent the interface from receiving any additional traffic. The only exception is Resource Reservation Protocol (RSVP) service, which if exploited, will cause the device to crash. Only the interface on which the vulnerability was exploited will be affected. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+User+Datagram+Protocol+Delivery+Issue+For+IPv4/IPv6+Dual-stack+Routers" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008096986d.shtml</guid>
    <pubDate>Fri, 25 Apr 2008 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Network Admission Control Shared Secret Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008097bea0.shtml</link>
    <description>A vulnerability exists in the Cisco Network Admission Control (NAC) Appliance that can allow an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM). &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Network+Admission+Control+Shared+Secret+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008097bea0.shtml</guid>
    <pubDate>Fri, 25 Apr 2008 11:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple DLSw Denial of Service Vulnerabilities in Cisco IOS</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080969866.shtml</link>
    <description>Cisco IOS contains multiple vulnerabilities in the Data-link Switching (DLSw) feature that may result in a reload or memory leaks when processing specially crafted UDP or IP Protocol 91 packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+DLSw+Denial+of+Service+Vulnerabilities+in+Cisco+IOS" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080969866.shtml</guid>
    <pubDate>Fri, 25 Apr 2008 05:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Disaster Recovery Framework Command Execution Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml</link>
    <description>Several products in the Cisco Unified Communications family of products contain a command execution vulnerability in the Disaster Recovery Framework (DRF) feature. A remote, unauthenticated user could exploit this vulnerability to execute arbitrary commands that may allow full administrative access to affected systems. There is a workaround for this vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Disaster+Recovery+Framework+Command+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008096fd9a.shtml</guid>
    <pubDate>Thu, 03 Apr 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>SQL injection in Cisco Unified Communications Manager</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml</link>
    <description>Cisco Unified Communications Manager is vulnerable to a SQL Injection attack in the parameter key of the admin and user interface pages.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=SQL+injection+in+Cisco+Unified+Communications+Manager" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml</guid>
    <pubDate>Thu, 03 Apr 2008 05:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Multicast Virtual Private Network (MVPN) Data Leak</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080969868.shtml</link>
    <description>This Applied Mitigation Bulletin is a companion document to the PSIRT 	 Security Advisory Cisco IOS Multicast Virtual Private Network (MVPN) Data Leak and provides identification and mitigation techniques that administrators can deploy on Cisco network devices.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Multicast+Virtual+Private+Network+(MVPN)+Data+Leak" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080969868.shtml</guid>
    <pubDate>Fri, 28 Mar 2008 18:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Virtual Private Dial-up Network Denial of Service Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080969862.shtml</link>
    <description>Two vulnerabilities exist in the virtual private dial-up network (VPDN) solution when Point-to-Point Tunneling Protocol (PPTP) is used in certain Cisco IOS releases prior to 12.3. PPTP is only one of the supported tunneling protocols used to tunnel PPP frames within the VPDN solution.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Virtual+Private+Dial-up+Network+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080969862.shtml</guid>
    <pubDate>Fri, 28 Mar 2008 17:30:00 PST</pubDate>
  </item>
  <item>
    <title>Vulnerability in Cisco IOS with OSPF, MPLS VPN, and Supervisor 32, Supervisor 720, or Route Switch Processor 720</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080969882.shtml</link>
    <description>Certain Cisco Catalyst 6500 Series and Cisco 7600 Router devices that	 run branches of Cisco IOS based on 12.2 can be vulnerable to a denial of service vulnerability that can prevent any traffic from entering an affected interface. For a device to be vulnerable, it must be configured for Open Shortest Path First (OSPF) Sham-Link and Multi Protocol Label Switching (MPLS) Virtual Private Networking (VPN). This vulnerability only affects Cisco Catalyst 6500 Series or Catalyst 7600 Series devices with the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720) or Route Switch Processor 720 RSP720) modules. The Supervisor 32, Supervisor 720, Supervisor 720-3B, Supervisor 720-3BXL, Route Switch Processor 720, Route Switch Processor 720-3C, and Route Switch Processor 720-3CXL are all potentially vulnerable.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Vulnerability+in+Cisco+IOS+with+OSPF,+MPLS+VPN,+and+Supervisor+32,+Supervisor+720,+or+Route+Switch+Processor+720" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080969882.shtml</guid>
    <pubDate>Wed, 26 Mar 2008 09:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Secure Access Control Server for Windows User-Changeable Password Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml</link>
    <description>Two sets of vulnerabilities were discovered in the Cisco Secure Access Control Server (ACS) for Windows User-Changeable Password (UCP) application and reported to Cisco by Felix 'FX' Lindner, Recurity Labs GmbH.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Secure+Access+Control+Server+for+Windows+User-Changeable+Password+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008095f0c4.shtml</guid>
    <pubDate>Fri, 14 Mar 2008 05:00:00 PST</pubDate>
  </item>
  <item>
    <title>CiscoWorks Internetwork Performance Monitor Remote Command Execution Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008095ff31.shtml</link>
    <description>CiscoWorks Internetwork Performance Monitor (IPM) version 2.6 for Sun Solaris and Microsoft Windows operating systems contains a vulnerability that allows remote, unauthenticated users to execute arbitrary commands. There are no workarounds for this vulnerability. Cisco has made free software available to address this issue for affected customers.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=CiscoWorks+Internetwork+Performance+Monitor+Remote+Command+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008095ff31.shtml</guid>
    <pubDate>Thu, 13 Mar 2008 13:30:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml</link>
    <description>Cisco Unified IP Phone models contain multiple overflow and denial of service (DoS) vulnerabilities.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+IP+Phone+Overflow+and+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml</guid>
    <pubDate>Wed, 13 Feb 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Wireless Control System Tomcat mod_jk.so Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml</link>
    <description>Apache Tomcat is the servlet container for JavaServlet and JavaServer Pages Web within the Cisco Wireless Control System (WCS). A vulnerability exists in the mod_jk.so URI handler within Apache Tomcat which, if exploited, may result in a remote code execution attack.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Wireless+Control+System+Tomcat+mod_jk.so+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml</guid>
    <pubDate>Wed, 30 Jan 2008 06:50:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco PIX and ASA Time-to-Live Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008093942e.shtml</link>
    <description>A crafted IP packet vulnerability exists in the Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA) that may result in a reload of the device. This vulnerability is triggered during processing of a crafted IP packet when the Time-to-Live (TTL) decrement feature is enabled.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+PIX+and+ASA+Time-to-Live+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008093942e.shtml</guid>
    <pubDate>Wed, 23 Jan 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Default Passwords in the Application Velocity System</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080939431.shtml</link>
    <description>Versions of the Cisco Application Velocity System (AVS) prior to software version AVS 5.1.0 do not prompt users to modify system account passwords during the initial configuration process. Because there is no requirement to change these credentials during the initial configuration process, an attacker may be able to leverage the accounts that have default credentials, some of which have root privileges, to take full administrative control of the AVS system.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Default+Passwords+in+the+Application+Velocity+System" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080939431.shtml</guid>
    <pubDate>Wed, 23 Jan 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager CTL Provider Heap Overflow</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml</link>
    <description>Cisco Unified Communications Manager (CUCM), formerly CallManager, contains a heap overflow vulnerability in the Certificate Trust List (CTL) Provider service that could allow a remote, unauthenticated user to cause a denial of service (DoS) condition or execute arbitrary code. There is a workaround for this vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+CTL+Provider+Heap+Overflow" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080932c61.shtml</guid>
    <pubDate>Wed, 16 Jan 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>TCP Vulnerabilities in Multiple Non-IOS Cisco Products</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008021ba2f.shtml</link>
    <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=TCP+Vulnerabilities+in+Multiple+Non-IOS+Cisco+Products" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008021ba2f.shtml</guid>
    <pubDate>Tue, 08 Jan 2008 06:00:00 PST</pubDate>
  </item>
  <item>
    <title>Application Inspection Vulnerability in Cisco Firewall Services Module</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008091b11d.shtml</link>
    <description>A vulnerability exists in the Cisco Firewall Services Module (FWSM) - a high-speed, integrated firewall module for Cisco Catalyst 6500 switches and Cisco 7600 Series routers, that may result in a reload of the FWSM. The only affected FWSM System Software Version is 3.2(3).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Application+Inspection+Vulnerability+in+Cisco+Firewall+Services+Module" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008091b11d.shtml</guid>
    <pubDate>Thu, 03 Jan 2008 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Security Agent for Windows Csatdi.sys Remote Buffer Overflow Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008090a434.shtml</link>
    <description>A buffer overflow vulnerability exists in a system driver used by the Cisco Security Agent for Microsoft Windows. This buffer overflow can be exploited remotely and causes corruption of kernel memory, which leads to a Windows stop error (blue screen) or to arbitrary code execution.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Security+Agent+for+Windows+Csatdi.sys+Remote+Buffer+Overflow+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008090a434.shtml</guid>
    <pubDate>Wed, 05 Dec 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Firewall Services Module (2)</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtml</link>
    <description>Two crafted packet vulnerabilities exist in the Cisco Firewall Services Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities can be triggered during the processing of HTTPS requests, or during the processing of Media Gateway Control Protocol (MGCP) packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Firewall+Services+Module+(2)" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda61.shtml</guid>
    <pubDate>Wed, 31 Oct 2007 10:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco PIX and ASA Appliance</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda56.shtml</link>
    <description>Two crafted packet vulnerabilities exist in the Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA) that may result in a reload of the device. These vulnerabilities are triggered during processing of Media Gateway Control Protocol (MGCP) packets, or during processing of Transport Layer Security (TLS) traffic that terminates on the PIX or ASA security appliance.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+PIX+and+ASA+Appliance" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda56.shtml</guid>
    <pubDate>Fri, 19 Oct 2007 13:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Web-based Management Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda12.shtml</link>
    <description>Unified Contact Center and Intelligent Contact Management products contain a vulnerability that may result in unauthorized access to the web-based reporting and script monitoring tool (Web View) and the web-based configuration tool (Web Admin).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Web-based+Management+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda12.shtml</guid>
    <pubDate>Wed, 17 Oct 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager Denial of Service Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtml</link>
    <description>Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two denial of service (DoS) vulnerabilities. Large volumes of UDP Session Initiation Protocol (SIP) INVITE messages may cause a resource exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM Trivial File Transfer Protocol (TFTP) service contains a buffer overflow vulnerability that may result in a denial of service condition or allow a remote, unauthenticated user to execute arbitrary code. There are no workarounds for these vulnerabilities.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtml</guid>
    <pubDate>Wed, 17 Oct 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Wireless Control System Conversion Utility Adds Default Password</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808d72db.shtml</link>
    <description>Customers who use the CiscoWorks Wireless LAN Solution Engine (WLSE) may use a conversion utility to convert over to a Cisco Wireless Control System (WCS). This conversion utility creates and uses administrative accounts with default credentials. Because there is no requirement to change these credentials during the conversion process, an attacker may be able to leverage the accounts that have default credentials to take full administrative control of the WCS after the conversion has been completed. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Wireless+Control+System+Conversion+Utility+Adds+Default+Password" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808d72db.shtml</guid>
    <pubDate>Wed, 10 Oct 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Local Privilege Escalation Vulnerabilities in Cisco VPN Client</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808a0554.shtml</link>
    <description>Two vulnerabilities exist in the Cisco VPN Client for Microsoft Windows that may allow unprivileged users to elevate their privileges to those of the LocalSystem account. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Local+Privilege+Escalation+Vulnerabilities+in+Cisco+VPN+Client" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808a0554.shtml</guid>
    <pubDate>Wed, 12 Sep 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808b4d38.shtml</link>
    <description>Cisco Video Surveillance IP Gateway video encoder and decoder, Services Platform (SP), and Integrated Services Platform (ISP) devices contain authentication vulnerabilities that allow remote users with network connectivity to gain the complete administrative control of vulnerable devices. There are no workarounds for these vulnerabilities.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Video+Surveillance+IP+Gateway+and+Services+Platform+Authentication+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808b4d38.shtml</guid>
    <pubDate>Wed, 05 Sep 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Denial of Service Vulnerabilities in Content Switching Module</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808b4d3b.shtml</link>
    <description>The Cisco Content Switching Modules (CSM) and Cisco Content Switching Module with SSL (CSM-S) contain two vulnerabilities that can lead to a denial of service (DoS) condition. The first vulnerability exists when processing TCP packets, and the second vulnerability affects devices with service termination enabled.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerabilities+in+Content+Switching+Module" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808b4d3b.shtml</guid>
    <pubDate>Wed, 05 Sep 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808ae327.shtml</link>
    <description>Cisco CallManager and Unified Communications Manager are vulnerable to 	 cross-site Scripting (XSS) and SQL Injection attacks in the lang variable of the admin and user logon pages. A successful attack may allow an attacker to run JavaScript on computer systems connecting to CallManager or Unified Communications Manager servers, and has the potential to disclose information within the database.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=XSS+and+SQL+Injection+in+Cisco+CallManager/Unified+Communications+Manager+Logon+Page" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808ae327.shtml</guid>
    <pubDate>Fri, 31 Aug 2007 13:00:00 PST</pubDate>
  </item>
  <item>
    <title>Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtml</link>
    <description>Multiple voice-related vulnerabilities are identified in Cisco IOS software, one of which is also shared with Cisco Unified Communications Manager. These vulnerabilities pertain to the following protocols or features: &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Voice+Vulnerabilities+in+Cisco+IOS+and+Cisco+Unified+Communications+Manager" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtml</guid>
    <pubDate>Mon, 20 Aug 2007 06:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Next Hop Resolution Protocol Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008089963b.shtml</link>
    <description>The Cisco Next Hop Resolution Protocol (NHRP) feature in Cisco IOS. contains a vulnerability that can result in a restart of the device or possible remote code execution.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Next+Hop+Resolution+Protocol+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008089963b.shtml</guid>
    <pubDate>Fri, 10 Aug 2007 08:00:00 PST</pubDate>
  </item>
  <item>
    <title>Information Leakage Using IPv6 Routing Header in Cisco IOS and Cisco IOS-XR</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080899647.shtml</link>
    <description>Cisco IOS and Cisco IOS XR contain a vulnerability when processing specially crafted IPv6 packets with a Type 0 Routing Header present. Exploitation of this vulnerability can lead to information leakage on affected IOS and IOS XR devices, and may also result in a crash of the affected IOS device. Successful exploitation on an affected device running Cisco IOS XR will not result in a crash of the device itself, but may result in a crash of the IPv6 subsystem. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Information+Leakage+Using+IPv6+Routing+Header+in+Cisco+IOS+and+Cisco+IOS-XR" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080899647.shtml</guid>
    <pubDate>Thu, 09 Aug 2007 09:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco IOS Secure Copy Authorization Bypass Vulnerability</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080899636.shtml</link>
    <description>The server side of the Secure Copy (SCP) implementation in Cisco Internetwork Operating System (IOS) contains a vulnerability that allows any valid user, regardless of privilege level, to transfer files to and from an IOS device that is configured to be a Secure Copy server. This vulnerability could allow valid users to retrieve or write to any file on the device's filesystem, including the device's saved configuration. This configuration file may include passwords or other sensitive information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Secure+Copy+Authorization+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080899636.shtml</guid>
    <pubDate>Wed, 08 Aug 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Wireless ARP Storm Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008088ab28.shtml</link>
    <description>Cisco Wireless LAN Controllers (WLC) contain multiple vulnerabilities in the handling of Address Resolution Protocol (ARP) packets that could result in a denial of service (DoS) in certain environments.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Wireless+ARP+Storm+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008088ab28.shtml</guid>
    <pubDate>Tue, 31 Jul 2007 05:35:00 PST</pubDate>
  </item>
  <item>
    <title>Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080883d10.shtml</link>
    <description>The Cisco Wide Area Application Services (WAAS) software contains a denial of service (DoS) vulnerability that may cause some devices that run WAAS software (WAE appliance and NM-WAE-502 module) to stop processing all types of traffic, including data traffic and management traffic. This condition may occur if a device running WAAS software is configured for Edge Services, which utilizes Common Internet File System (CIFS) optimization and receives a flood of TCP SYN packets on port 139 or 445.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerability+in+Cisco+Wide+Area+Application+Services+(WAAS)+Software" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080883d10.shtml</guid>
    <pubDate>Sat, 21 Jul 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager Overflow Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008087d188.shtml</link>
    <description>Cisco Unified Communications Manager (CUCM), formerly CallManager, and Cisco Unified Presence Server (CUPS) contain two vulnerabilities that could allow an unauthorized administrator to activate and terminate CUCM / CUPS system services and access SNMP configuration information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Overflow+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008087d188.shtml</guid>
    <pubDate>Wed, 11 Jul 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Cisco Unified Communications Manager and Presence Server Unauthorized Access Vulnerabilities</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008087d189.shtml</link>
    <description>Cisco Unified Communications Manager (CUCM), formerly CallManager, and Cisco Unified Presence Server (CUPS) contain two vulnerabilities that could allow an unauthorized administrator to activate and terminate CUCM / CUPS system services and access SNMP configuration information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+and+Presence+Server+Unauthorized+Access+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008087d189.shtml</guid>
    <pubDate>Wed, 11 Jul 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Vulnerability In Crypto Library</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c5d.shtml</link>
    <description>A vulnerability has been discovered in a third party cryptographic library which is used by a number of Cisco products. This vulnerability may be triggered when a malformed Abstract Syntax Notation One (ASN.1) object is parsed. Due to the nature of the vulnerability it may be possible, in some cases, to trigger this vulnerability without a valid certificate or valid application-layer credentials (such as a valid username or password).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Vulnerability+In+Crypto+Library" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c5d.shtml</guid>
    <pubDate>Thu, 28 Jun 2007 07:00:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Cisco IOS While Processing SSL Packets</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c49.shtml</link>
    <description>Cisco IOS devices may crash while processing malformed Secure Sockets Layer (SSL) packets. In order to trigger these vulnerabilities, a malicious client must send malformed packets during the SSL protocol exchange with the vulnerable device.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+IOS+While+Processing+SSL+Packets" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a0080847c49.shtml</guid>
    <pubDate>Wed, 27 Jun 2007 06:50:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in Wireless Control System</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00806cd85a.shtml</link>
    <description>Cisco Wireless Control System (WCS) contains multiple vulnerabilities which may allow a remote user to access sensitive configuration information about access points managed by WCS, read from and write to arbitrary files on a WCS system, log in to a WCS system with a default administrator password, execute script code in a WCS user's web browser,  and access directories which may reveal sensitive WCS configuration information. There are workarounds for several, but not all, of these vulnerabilities. See the Workarounds section for more information. Cisco has made free software available to address these vulnerabilities for affected customers.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Wireless+Control+System" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00806cd85a.shtml</guid>
    <pubDate>Thu, 31 May 2007 18:30:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in the Cisco Wireless LAN Controller and Cisco Lightweight Access Points</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a008081e189.shtml</link>
    <description>The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+the+Cisco+Wireless+LAN+Controller+and+Cisco+Lightweight+Access+Points" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a008081e189.shtml</guid>
    <pubDate>Wed, 16 May 2007 13:30:00 PST</pubDate>
  </item>
  <item>
    <title>Multiple Vulnerabilities in the IOS FTP Server</title>
    <link>http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml</link>
    <description>Multiple vulnerabilities exist in the Cisco IOS File Transfer Protocol (FTP) Server feature. These vulnerabilities include Denial of Service, improper verification of user credentials and the ability to read or write any file in the device's filesystem, including the device's saved configuration, which may include passwords or other sensitive information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+the+IOS+FTP+Server" border="0" height="0" width="0" /&gt;</description>
    <category>Cisco Security Advisory</category>
    <guid isPermaLink="true">http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml</guid>
    <pubDate>Wed, 09 May 2007 07:00:00 PST</pubDate>
  </item>
</channel>
   </rss>