• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Thursday, June 18, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home Tech

Bugs in Cisco BPA and WSA can allow remote cyberattacks

by Manasi Varma
July 11, 2021
in Tech
Reading Time: 2 mins read
0
How to protect yourself from hackers

Source: https://www.inc.com/kevin-daum/6-ways-you-can-protect-yourself-from-hacking.html

TwitterWhatsappLinkedin

As per a report by Threatpost, Cisco’s Web Security Applicance (WSA), which acts as a shield and automatically blocks high risk sites, as well as its Business Process Automation application, have been found to be suffering from a set of high-severity privilege-escalation vulnerabilities. These weaknesses in the programmes could open up a gateway for authenticated attackers working remotely, go hack in sensitive data or hijack systems, through Cisco BPA and WSA.

You might also like

Apple Considers iPhone Price Hike as Memory Chip Shortage Puts Pressure on Costs

Are metal credit cards in India worth the premium fees and benefits today?

Dreame Technology Unveils High-Performance L50s Pro Ultra and L50 Ultra CE Robotic Vacuum Cleaners in India, Setting New Benchmarks in Suction Performance

Cisco BPA and WSA
Image Credits: Threatpost

What Vulnerabilities?

The Cisco Business Process Automation (BPA) application, which is a tool used by organizations to align and speed up their IT processes, is faced by two major vulnerabilities, namely, CVE-2021-1574 and CVE-2021-1576. Each of these flaws is rated at 8.8 out of 10 on the CVSS vulnerability-severity scale, and can grant authenticated, remote attackers, access to privilege elevation up to the administrator level. What this means is that the hackers will get access to data that is normally only accessible to the administrators. As per an advisory released by Cisco on Thursday, these vulnerabilities have arisen due to “improper authorization enforcement” for a few features, as well as for access to the log files containing sensitive information. If hackers decide to exploit these flaws, they can, rather easily, “perform unauthorized actions” by posing as admins, or extract sensitive data, and use it for information.

The former of the two vulnerabilities will allow authorized attackers (those who have valid login credentials) to carry out unauthorised tasks. On the other hand, the latter can allow authorized hackers to hack into the logging subsystems, and extract data. This can be done only when a legit user is holding a session on the system active.

A third flaw has also been identified, and affects the WSA at Cisco. Having a score of 6.3 out of 10 on the CVSS scale, the CVE-2021-1359 vulnerability has been found to be located in the configuration management of WSA’s AsyncOS operating system. Hackers can make use of this vulnerability to elevate privilege to root, and perform command injection.

The reason for this flaw is said to be “insufficient validation” of the XML input supplied by users. Vulnerable devices may be attacked by hackers who send crafted XML configuration files to these devices. Such hacks can eventually lead to execution of arbitrary commands.

Trouble Strikes Again

This new set of vulnerabilities at Cisco BPA and WSA come after the firm previously rectified multiple high-severity flaws in its Small Business 220 Series Smart Switches line, just last month.

Tags: Business Process AutomationCiscoWeb Security Appliance
Tweet54SendShare15
Previous Post

How to get ESPN plus on iPhone and Android

Next Post

Samsung quietly introduces web version of TV Plus

Manasi Varma

A 20-something year old with a flair for writing, a love for reading, and an obsession for KPop. Most amicable person you'll ever meet.

Recommended For You

Apple Considers iPhone Price Hike as Memory Chip Shortage Puts Pressure on Costs

by Rounak Majumdar
June 18, 2026
0
Apple Considers iPhone Price Hike as Memory Chip Shortage Puts Pressure on Costs

Apple may be forced to increase iPhone prices in the coming months as a global shortage of memory chips continues to drive up production costs. The possibility was...

Read more

Are metal credit cards in India worth the premium fees and benefits today?

by Rohan Mathawan
June 18, 2026
0
Photo by Ales Nesetril on Unsplash

Premium metal credit cards are no longer rare in India. More issuers now offer variants with annual fees that vary significantly by issuer and card tier, from a...

Read more

Dreame Technology Unveils High-Performance L50s Pro Ultra and L50 Ultra CE Robotic Vacuum Cleaners in India, Setting New Benchmarks in Suction Performance

by Rohan Mathawan
June 18, 2026
0
Dreame Technology Unveils High-Performance L50s Pro Ultra and L50 Ultra CE Robotic Vacuum Cleaners in India, Setting New Benchmarks in Suction Performance

Dreame Technology, a global leader in smart home innovation, today announced the launch of two premium robotic vacuum cleaners in India, the Dreame L50s Pro Ultra and Dreame...

Read more
Next Post
Samsung quietly introduces web version of TV Plus

Samsung quietly introduces web version of TV Plus

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?