AI Security AI安全 18h ago Updated 14h ago 更新于 14小时前 41

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 思科修复九个Crosswork和Secure Workload漏洞,五个评分CVSS 10.0

Cisco patched nine critical vulnerabilities across its Crosswork platforms and Secure Workload products, five of which scored a maximum CVSS 10.0 Four Crosswork flaws include SQL injection, missing authentication, external file system control, and insufficiently protected credentials, all affecting versions 7.2.1 and earlier Five Secure Workload vulnerabilities span command injection, improper access control, authentication bypass, input validation flaws, and buffer overflow issues All issues we Cisco发布安全更新,修复Crosswork平台和Secure Workload软件中的9个漏洞,其中5个CVSS评分为10.0(最高严重级别) Crosswork平台4个漏洞影响Data Gateway、Network Controller和Planning组件,涉及SQL注入、缺少认证、文件系统控制等高危问题 Secure Workload 5个漏洞覆盖命令注入、访问控制缺陷、认证绕过、路径遍历和缓冲区溢出,影响SaaS和本地部署 所有漏洞均通过内部安全审查发现,目前未发现被主动利用,但Cisco敦促客户尽快更新 受影响版本:Crosswork 7.2.1及更早(修复于7.2.1-SP)

58
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Cisco patched nine critical vulnerabilities across its Crosswork platforms and Secure Workload products, five of which scored a maximum CVSS 10.0
  • Four Crosswork flaws include SQL injection, missing authentication, external file system control, and insufficiently protected credentials, all affecting versions 7.2.1 and earlier
  • Five Secure Workload vulnerabilities span command injection, improper access control, authentication bypass, input validation flaws, and buffer overflow issues
  • All issues were discovered during internal testing and are not known to be actively exploited, though Cisco urges immediate patching
  • This follows a broader internal security review that has already addressed 12 bugs in Catalyst SD-WAN and IOS XE, plus a separately exploited firewall vulnerability (CVE-2026-20349)

Why It Matters

Cisco's networking and security infrastructure is deeply embedded in enterprise environments worldwide, making mass exploitation of these flaws a high-impact scenario for threat actors. The concentration of CVSS 10.0 vulnerabilities—particularly authentication bypass and SQL injection—means a single compromised instance could lead to full system takeover with no prior credentials. This ongoing internal security review signals a proactive shift in Cisco's vulnerability management posture, which has direct implications for how enterprises prioritize patching cycles and assess their exposure to widely deployed Cisco platforms.

Technical Details

  • Crosswork Vulnerabilities (4 flaws): CVE-2026-20030 (SQL injection, CVSS 10.0), CVE-2026-20357 (missing authentication for critical functions, CVSS 10.0), CVE-2026-20358 (external control of file system, CVSS 10.0), and CVE-2026-20359 (insufficiently protected credentials, CVSS 9.9). All affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning regardless of device configuration. Patched in Crosswork Release 7.2.1-SP.
  • Secure Workload Vulnerabilities (5 flaws): CVE-2026-20231 (command/OS/argument injection, CVSS 9.9), CVE-2026-20315 (improper access control spanning authorization and privilege bypass, CVSS 10.0), CVE-2026-20317 (authentication bypass and reliance on untrusted inputs, CVSS 10.0), CVE-2026-20318 (input validation, path traversal, external path control, CVSS 9.6), and CVE-2026-20319 (buffer overflow and out-of-bounds writes, CVSS 7.5). Fixed in Secure Workload 3.10.9.1 and 4.0.4.16.
  • Patch versions: Crosswork 7.2.1-SP; Secure Workload 3.10.9.1 (for releases 3.10 and earlier) and 4.0.4.16 (for release 4.0).
  • Context: These patches are part of a comprehensive internal security review that previously addressed 12 bugs in Catalyst SD-WAN and IOS XE Software. A separate vulnerability in Secure Firewall ASA/FTD (CVE-2026-20349, CVSS 8.6) has already been exploited in the wild.

Industry Insight

  • Enterprises running Cisco Crosswork or Secure Workload should treat these patches as critical priority, especially given the authentication bypass and SQL injection flaws that require no prior access for exploitation.
  • The pattern of internally discovered vulnerabilities across multiple product lines suggests Cisco's security review program is effective at surface-level remediation, but organizations should audit their own configurations and network segmentation to limit blast radius while patches are deployed.
  • With Cisco gear being a repeatedly targeted vector by threat actors, the coexistence of unexploited critical flaws alongside an actively exploited firewall vulnerability underscores the importance of maintaining strict update cadences and monitoring for emerging threat intelligence related to Cisco product lines.

TL;DR

  • Cisco发布安全更新,修复Crosswork平台和Secure Workload软件中的9个漏洞,其中5个CVSS评分为10.0(最高严重级别)
  • Crosswork平台4个漏洞影响Data Gateway、Network Controller和Planning组件,涉及SQL注入、缺少认证、文件系统控制等高危问题
  • Secure Workload 5个漏洞覆盖命令注入、访问控制缺陷、认证绕过、路径遍历和缓冲区溢出,影响SaaS和本地部署
  • 所有漏洞均通过内部安全审查发现,目前未发现被主动利用,但Cisco敦促客户尽快更新
  • 受影响版本:Crosswork 7.2.1及更早(修复于7.2.1-SP),Secure Workload 3.10及更早(修复于3.10.9.1)、4.0(修复于4.0.4.16)

为什么值得看

Cisco作为企业网络基础设施的核心供应商,其产品漏洞直接影响全球大量企业的网络安全。此次批量修复高危漏洞(5个满分10.0)凸显了网络设备软件供应链安全的重要性,提醒AI从业者关注基础设施层的安全风险。

技术解析

  • Crosswork平台漏洞:CVE-2026-20030(SQL注入,CVSS 10.0)、CVE-2026-20357(关键功能缺少认证,CVSS 10.0)、CVE-2026-20358(外部控制文件系统,CVSS 10.0)、CVE-2026-20359(凭证保护不足,CVSS 9.9),影响所有设备配置
  • Secure Workload漏洞:CVE-2026-20231(命令/OS/参数注入,CVSS 9.9)、CVE-2026-20315(访问控制缺陷,CVSS 10.0)、CVE-2026-20317(认证绕过,CVSS 10.0)、CVE-2026-20318(输入验证/路径遍历,CVSS 9.6)、CVE-2026-20319(缓冲区溢出,CVSS 7.5)
  • 修复版本:Crosswork升级至7.2.1-SP;Secure Workload分别升级至3.10.9.1和4.0.4.16
  • 发现方式:通过Cisco内部全面安全审查发现,非外部披露,目前无在野利用证据
  • 关联背景:约两周前Cisco刚修复Catalyst SD-WAN和IOS XE的12个漏洞,本月早些时候还警告了Secure Firewall ASA/FTD的CVE-2026-20349(CVSS 8.6)已在野利用

行业启示

  • 网络设备供应链安全需持续关注:Cisco作为企业网络核心供应商,其产品频繁成为攻击目标,企业应将网络设备软件更新纳入常态化安全运维流程
  • 内部安全审查的价值:Cisco通过内部审查主动发现并修复高危漏洞,体现了"主动安全"优于"被动响应"的策略,值得行业借鉴
  • 高危漏洞的连锁风险:5个CVSS 10.0漏洞集中在认证和访问控制领域,攻击者一旦利用可完全控制受影响系统,企业需优先评估这些漏洞的暴露面并紧急修补

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全