<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Management Archives - ICT News</title>
	<atom:link href="https://www.ict-news.org/tag/management/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.ict-news.org</link>
	<description>Information &#38; Communication technology world news</description>
	<lastBuildDate>Sat, 11 Mar 2017 13:58:54 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.3</generator>

<image>
	<url>https://www.ict-news.org/wp-content/uploads/2018/03/ICT-icon-3.png</url>
	<title>Management Archives - ICT News</title>
	<link>https://www.ict-news.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cisco patches critical flaw in Prime Home device management server</title>
		<link>https://www.ict-news.org/review-3-services-managing-cloud-storage-accounts/</link>
					<comments>https://www.ict-news.org/review-3-services-managing-cloud-storage-accounts/#respond</comments>
		
		<dc:creator><![CDATA[lukasik]]></dc:creator>
		<pubDate>Fri, 03 Feb 2017 10:44:03 +0000</pubDate>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://newsroom.ict-hardware.com/?p=7446</guid>

					<description><![CDATA[<p>The post <a rel="nofollow" href="https://www.ict-news.org/review-3-services-managing-cloud-storage-accounts/">Cisco patches critical flaw in Prime Home device management server</a> appeared first on <a rel="nofollow" href="https://www.ict-news.org">ICT News</a>.</p>
]]></description>
										<content:encoded><![CDATA[<section class="container-wrap  main-color "  style="padding-top:40px;padding-bottom:40px" ><div class="section-container container"><div class="vc_row vc_row-fluid row"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner "><div class="wpb_wrapper">
	<div class="kleo_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<h2>The vulnerability could allow hackers to take over servers used by ISPs to manage subscribers and their gateway devices</h2>
<p>Cisco Systems has fixed a critical vulnerability that could allow hackers to take over servers used by telecommunications providers to remotely manage customer equipment such as routers.</p>
<p>The vulnerability affects Cisco Prime Home, an automated configuration server (ACS) that communicates with subscriber devices using the TR-069 protocol. In addition to remotely managing customer equipment, it can also &#8220;automatically activate and configure subscribers and deliver advanced services via service packages&#8221; over mobile, fiber, cable, and other ISP networks.</p>
<p>&#8220;A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges,&#8221; Cisco said in <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-prime-home" target="_blank">its advisory</a>.</p>
<p>Attackers could exploit the vulnerability by sending API commands over HTTP to a particular URL without requiring authentication. The flaw is caused by a processing error in the role-based access control of URLs, Cisco explained.</p>
<aside class="nativo-promo smartphone"></aside>
<p>In the past, security researchers found vulnerabilities in the TR-069 implementation of many routers that could have allowed hackers to remotely take over those devices. However, a vulnerability in an ACS like Cisco Prime Home is much worse, because it can be used to take control of entire groups of subscriber devices at once.</p>
<p>According to Cisco&#8217;s <a href="https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/home/5-1/user/guide/cisco_prime_home_5-1_user_guide/prime_home_5-1_ug_ch1_intro.html" target="_blank">documentation</a>, the admin role on the Cisco Prime Home has access to the server&#8217;s customer support, administration, and audit functions, as well as the ability to perform bulk operations and access utilities and reports.</p>
<p>The vulnerability affects Cisco Prime Home versions 6.3.0.0 and above. Customers are advised to migrate to the latest, fixed version: 6.5.0.1.</p>
<p>The company has also <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-psc" target="_blank">warned customers</a> of a medium-risk URL redirect vulnerability in the Cisco Prime Service Catalog, a product that allows companies to set up self-service portals, provide IT service catalogs for data center and application services, and manage service requests.</p>
<aside class="nativo-promo tablet desktop"></aside>
<p>An attacker could exploit the vulnerability to redirect a user logged into the Cisco Prime Service Catalog to a phishing site in order to steal their credentials.</p>
<p>By <span class="fn"><a href="http://www.computerworld.com/author/Lucian-Constantin/" rel="author">Lucian Constantin</a>, source by <a href="http://www.computerworld.com/">ComputerWorld</a></span></p>
<p>Visit <a href="https://www.ict-hardware.com/">ICT Hardware</a> to get more info about <a href="https://www.ict-hardware.com/">Cisco Products</a></p>

		</div> 
	</div> </div></div></div></div></div></section><!-- end section -->
<p>The post <a rel="nofollow" href="https://www.ict-news.org/review-3-services-managing-cloud-storage-accounts/">Cisco patches critical flaw in Prime Home device management server</a> appeared first on <a rel="nofollow" href="https://www.ict-news.org">ICT News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.ict-news.org/review-3-services-managing-cloud-storage-accounts/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
