So Cisco really did drop a CVSS 10 on the day after the US election? I WAS FUCKING JOKING, CISCO!
@buherator Forgot to CTRL+V. Added to the original post. This one is also interesting though: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-sqli-CyPPAxrL
@buherator Good thing everyone's in a good place and ready to get it patched right away...
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system.
Yeeeikes. Uhhh, worth noting that I believe this class of device is commonly used for municipal wifi so...there's that?
@cR0w you might have been joking. Cisco unfortunately was not…again.