Cisco snaps shut remote pwnage hole in Cloud Services Platform
Cisco has provided a patch to address a remote hijacking vulnerability in its Cloud Services Platform (CSP).
Switchzilla said that all customers who run CSP 2100 software should install the 2.1.0 update to close a remote code execution flaw it considers to be a high security risk.
Designed as an efficient way to manage virtualized network services and components, CSP is installed as a Linux x86 virtual machine built into a Cisco network appliance. The system includes a web-based GUI for device management. Cisco says that the flaw (CVE-2016-6374) allows an attacker to send malformed HTTP requests to achieve remote code execution.