Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities NCSC Netherlands

NCSC-2026-0218 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Catalyst Center

Cisco has patched a vulnerability in Cisco Catalyst Center where insufficient validation of user-supplied input allows unauthenticated attackers to read arbitrary files within a limited container via crafted HTTP requests, potentially leading to information disclosure. The vulnerability is tracked as CVE-2024-20356 with a CVSS score of 6.5. Affected versions include Cisco Catalyst Center releases earlier than 2.3.7.4, and the fix is provided in release 2.3.7.4.
Read Full Article →

Cisco heeft een kwetsbaarheid verholpen in Cisco Catalyst Center. De kwetsbaarheid bevindt zich in de onvoldoende validatie van door gebruikers aangeleverde input, die via speciaal opgezette HTTP-verzoeken kan worden gemanipuleerd om toegang te krijgen tot bestanden binnen een beperkte container. Hierdoor kunnen niet-geauthenticeerde aanvallers willekeurige bestanden lezen zonder authenticatie, wat kan leiden tot het blootstellen van vertrouwelijke informatie. De kwetsbaarheid wordt specifiek misbruikt via HTTP-requestmanipulatie.

Share this article