Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Here is the original vulnerability report: https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-0...


... which has

    -A kurl
in the proof of concept.

I also note the timeline

* 2019-01-22 Firmware 1.4.2.20 released by vendor

...

* 2019-02-07 Incomplete mitigation of vulnerability identified

...

* 2019-03-25 Vendor requests postponed disclosure

So this is apparently a bad fix that Cisco has known about since February, and asked for an extension in order to fix again.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: