Close Menu
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
Trending

Deadliest Catch Star Todd Meadows Dies at 25 in Tragic Bering Sea Fall

March 5, 2026

US Launches Joint Ops in Ecuador Against Narco-Terrorists

March 5, 2026

Sony Reinstates PS Exclusivity for Major Hits, Halts PC Ports

March 5, 2026

Son Reveals Grandmother’s Verbal Abuse, Mom Faces Custody Dilemma

March 5, 2026

Toronto Drug Trafficker Barred from Contacting Ryan Wedding Ally

March 5, 2026

Tottenham in Shock Talks to Re-Sign Dele Alli as Free Agent

March 5, 2026

Ecuador Expels Cuban Ambassador and Staff in Diplomatic Clash

March 5, 2026
Facebook X (Twitter) Instagram
VernoNews
  • Home
  • World
  • National
  • Science
  • Business
  • Health
  • Education
  • Lifestyle
  • Entertainment
  • Sports
  • Technology
  • Gossip
VernoNews
Home»Technology»Cisco warns of a severe safety flaw in comms platform – and that it wants patching instantly
Technology

Cisco warns of a severe safety flaw in comms platform – and that it wants patching instantly

VernoNewsBy VernoNewsJuly 3, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Reddit WhatsApp Email
Cisco warns of a severe safety flaw in comms platform – and that it wants patching instantly
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

[ad_1]

Cisco warns of a severe safety flaw in comms platform – and that it wants patching instantly


  • Login credentials for an account with root entry was present in Cisco’s Unified Communications Supervisor
  • There are not any workarounds, only a patch, so customers ought to replace now
  • Totally different variations of the software are affected

One other hardcoded credential for admin entry has been found in a serious software program utility – this time round it’s Cisco, who found the slip-up in its Unified Communications Supervisor (Unified CM) resolution.

Cisco Unified CM is an enterprise-grade IP telephony name management platform offering voice, video, messaging, mobility, and presence companies. It manages voice-over-IP (VoIP) calls, and permits for the administration of duties similar to person/machine provisioning, voicemail integration, conferencing, and extra.

Lately, Cisco discovered login credentials coded into this system, permitting for entry with root privileges. The bug is now tracked as CVE-2025-20309, and was given a most severity rating – 10/10 (crucial). The credentials had been apparently used throughout growth and testing, and may have been eliminated earlier than the product was shipped to the market.


It’s possible you’ll like

No proof of abuse

Cisco Unified CM and Unified CM SME Engineering Particular (ES) releases 15.0.1.13010-1 by 15.0.1.13017-1 had been mentioned to be affected, whatever the machine configuration. There are not any workarounds or mitigations, and the one strategy to tackle it’s to improve this system to model 15SU3 (July 2025).

“A vulnerability in Cisco Unified Communications Supervisor (Unified CM) and Cisco Unified Communications Supervisor Session Administration Version (Unified CM SME) might enable an unauthenticated, distant attacker to log in to an affected machine utilizing the basis account, which has default, static credentials that can’t be modified or deleted,” Cisco mentioned.

At press time, there was no proof of abuse within the wild.

Hardcoded credentials are one of many extra widespread causes of system infiltrations. Only recently Sitecore Expertise Platform, an enterprise-level content material administration system (CMS), held a hardcoded password for an inner person. It was only one letter – ‘b’ – which was tremendous straightforward to guess.

Signal as much as the TechRadar Professional e-newsletter to get all the highest information, opinion, options and steering your small business must succeed!

Roughly a yr in the past, safety researchers from Horizon3.ai discovered hardcoded credentials in SolarWinds’ Net Assist Desk.

Through BleepingComputer

You may additionally like

[ad_2]

Avatar photo
VernoNews

    Related Posts

    Sony Reinstates PS Exclusivity for Major Hits, Halts PC Ports

    March 5, 2026

    AI Job Apocalypse Fears Intensify with Tech Layoffs Surge

    March 4, 2026

    Ingalls Shipbuilding Marks Keel for USS Philadelphia (LPD 32)

    March 4, 2026
    Leave A Reply Cancel Reply

    Don't Miss
    Entertainment

    Deadliest Catch Star Todd Meadows Dies at 25 in Tragic Bering Sea Fall

    By VernoNewsMarch 5, 20260

    Todd Meadows, the 25-year-old newest crew member on Deadliest Catch, tragically died after falling overboard…

    US Launches Joint Ops in Ecuador Against Narco-Terrorists

    March 5, 2026

    Sony Reinstates PS Exclusivity for Major Hits, Halts PC Ports

    March 5, 2026

    Son Reveals Grandmother’s Verbal Abuse, Mom Faces Custody Dilemma

    March 5, 2026

    Toronto Drug Trafficker Barred from Contacting Ryan Wedding Ally

    March 5, 2026

    Tottenham in Shock Talks to Re-Sign Dele Alli as Free Agent

    March 5, 2026

    Ecuador Expels Cuban Ambassador and Staff in Diplomatic Clash

    March 5, 2026
    About Us
    About Us

    VernoNews delivers fast, fearless coverage of the stories that matter — from breaking news and politics to pop culture and tech. Stay informed, stay sharp, stay ahead with VernoNews.

    Our Picks

    Deadliest Catch Star Todd Meadows Dies at 25 in Tragic Bering Sea Fall

    March 5, 2026

    US Launches Joint Ops in Ecuador Against Narco-Terrorists

    March 5, 2026

    Sony Reinstates PS Exclusivity for Major Hits, Halts PC Ports

    March 5, 2026
    Trending

    Son Reveals Grandmother’s Verbal Abuse, Mom Faces Custody Dilemma

    March 5, 2026

    Toronto Drug Trafficker Barred from Contacting Ryan Wedding Ally

    March 5, 2026

    Tottenham in Shock Talks to Re-Sign Dele Alli as Free Agent

    March 5, 2026
    • Contact Us
    • Privacy Policy
    • Terms of Service
    2025 Copyright © VernoNews. All rights reserved

    Type above and press Enter to search. Press Esc to cancel.