Blog / tag

A critical flaw in Arista EOS allows unauthenticated attackers to inject traffic into internal network segments by abusing tunnel decapsulation endpoints — and Arista says no software patch is coming. The vulnerability is actively being exploited and has been added to CISA's Known Exploited Vulne...

A perfect-10 authentication bypass in Cisco's SD-WAN Controller and Manager lets unauthenticated attackers seize control of enterprise wide-area networks. Cisco confirms active exploitation, CISA issues Emergency Directive 26-03.

A 2022 privilege escalation vulnerability in Cisco SD-WAN software is now being actively exploited in the wild, four years after patches were released. Attackers with any valid local credential can chain two path traversal bugs to seize complete root control of routers, controllers, and orchestra...