Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
A vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass TACACS authorization on an affected device. An attacker could exploit this vulnerability by sending a crafted Secure Shell (SSH) request to an affected device. A successful exploit could allow the attacker to bypass TACACS authorization and execute a subset of CLI commands on the affected device.
A vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker with an administrator account that is configured with the nocli option to bypass authorization on an affected device. An attacker could exploit this vulnerability by sending a crafted SSH request to an affected device. A successful exploit could allow the attacker to bypass the nocli option and execute a subset of CLI commands on the affected device.
Cisco
Refer to Cisco advisory for the complete list of affected product and their respective patches.