<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>NaMeX RSS Aggregator</title>
    <link>http://www.namex.it/site/rss/security</link>
    <description>NaMeX RSS Aggregator</description>
    <item>
      <title>Attention: New Cisco Security Advisory RSS Feed Locations</title>
      <link>http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml</link>
      <description>Effective October 18, 2011, Cisco has replaced the existing RSS feeds for Cisco Security Advisories. The new RSS feeds for Cisco Security Advisories are available at http://tools.cisco.com/security/center/psirtrss10/CiscoSecurityAdvisory.xml and http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml.  The existing RSS feeds will continue to function until November 19, 2011.  They will not receive updates after this date.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Attention:+New+Cisco+Security+Advisory+RSS+Feed+Locations" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml</guid>
    </item>
    <item>
      <title>Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-camera</link>
      <description>A denial of service (DoS) vulnerability exists in the Cisco Video Surveillance IP Cameras 2421, 2500 series and 2600 series of devices. An unauthenticated, remote attacker could exploit this vulnerability by sending crafted RTSP TCP packets to an affected device. Successful exploitation prevents cameras from sending video streams, subsequently causing a reboot. The camera reboot is done automatically and does not require action from an operator.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerability+in+Cisco+Video+Surveillance+IP+Cameras" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-camera</guid>
    </item>
    <item>
      <title>Cisco Unified Contact Center Express Directory Traversal Vulnerability</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx</link>
      <description>Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) contain a directory traversal vulnerability that may allow a remote, unauthenticated attacker to retrieve arbitrary files from the filesystem. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Contact+Center+Express+Directory+Traversal+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-uccx</guid>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Directory Traversal Vulnerability</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm</link>
      <description>Cisco Unified Communications Manager contains a directory traversal vulnerability that may allow an unauthenticated, remote attacker to retrieve arbitrary files from the filesystem. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Directory+Traversal+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-cucm</guid>
    </item>
    <item>
      <title>Buffer Overflow Vulnerabilities in the Cisco WebEx Player</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex</link>
      <description>Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system with the privileges of a targeted user.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Buffer+Overflow+Vulnerabilities+in+the+Cisco+WebEx+Player" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-webex</guid>
    </item>
    <item>
      <title>Cisco Security Agent Remote Code Execution Vulnerabilities</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa</link>
      <description>Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to perform remote code execution on the affected device. These vulnerabilities are in a third-party library (Oracle Outside In) and are documented in CERT-CC Vulnerability Note VU#520721 at http://www.kb.cert.org/vuls/id/520721&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Security+Agent+Remote+Code+Execution+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa</guid>
    </item>
    <item>
      <title>Cisco Show and Share Security Vulnerabilities</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns</link>
      <description>The Cisco Show and Share webcasting and video sharing application contains two vulnerabilities. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Show+and+Share+Security+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns</guid>
    </item>
    <item>
      <title>CiscoWorks Common Services Arbitrary Command Execution Vulnerability</title>
      <link>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs</link>
      <description>CiscoWorks Common Services for Microsoft Windows contains a vulnerability that could allow an authenticated, remote attacker to execute arbitrary commands on the affected system with the privileges of a system administrator.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=CiscoWorks+Common+Services+Arbitrary+Command+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-cs</guid>
    </item>
    <item>
      <title>Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b98d0b.html</link>
      <description>A vulnerability exists in Cisco TelePresence Video Communication Server (VCS) due to improper validation of user-controlled input to the web-based administrative interface. User-controlled input supplied to the login page via the HTTP User-Agent header is not properly sanitized for illegal or malicious content prior to being returned to the user in dynamically generated web content. A remote attacker could exploit this vulnerability to perform reflected cross-site scripting attacks.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+TelePresence+Video+Communication+Server+Cross-Site+Scripting+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b98d0b.html</guid>
    </item>
    <item>
      <title>Cisco IOS Software Smart Install Remote Code Execution Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4f.shtml</link>
      <description>A vulnerability exists in the Smart Install feature of Cisco Catalyst Switches running Cisco IOS Software that could allow an unauthenticated, remote attacker to perform remote code execution on the affected device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Smart+Install+Remote+Code+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4f.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software IP Service Level Agreement Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4c.shtml</link>
      <description>The Cisco IOS IP Service Level Agreement (IP SLA) feature contains a denial of service (DoS) vulnerability. The vulnerability is triggered when malformed UDP packets are sent to a vulnerable device. The vulnerable UDP port numbers depend on the device configuration. Default ports are not used for the vulnerable UDP IP SLA operation or for the UDP responder ports.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IP+Service+Level+Agreement+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4c.shtml</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97900.shtml</link>
      <description>Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module are affected by multiple vulnerabilities as follows:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+ASA+5500+Series+Adaptive+Security+Appliances+and+Cisco+Catalyst+6500+Series+ASA+Services+Module" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97900.shtml</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Cisco Firewall Services Module</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97904.shtml </link>
      <description>The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers is affected by the following vulnerabilities:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+Firewall+Services+Module" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97904.shtml </guid>
    </item>
    <item>
      <title>Directory Traversal Vulnerability in Cisco Network Admission Control Manager</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97901.shtml </link>
      <description>Cisco Network Admission Control (NAC) Manager contains a directory traversal vulnerability that may allow an unauthenticated attacker to obtain system information.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Directory+Traversal+Vulnerability+in+Cisco+Network+Admission+Control+Manager" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b97901.shtml </guid>
    </item>
    <item>
      <title>Cisco Identity Services Engine Database Default Credentials Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtml</link>
      <description>Cisco Identity Services Engine (ISE) contains a set of default credentials for its underlying database. A remote attacker could use those credentials to modify the device configuration and settings or gain complete administrative control of the device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Identity+Services+Engine+Database+Default+Credentials+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtml</guid>
    </item>
    <item>
      <title>Cisco 10000 Series Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d50.shtml</link>
      <description>The Cisco 10000 Series Router is affected by a denial of service (DoS) vulnerability that can allow an attacker to cause a device reload by sending a series of ICMP packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+10000+Series+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d50.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software IPv6 over MPLS Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d52.shtml</link>
      <description>Cisco IOS Software is affected by two vulnerabilities that cause a Cisco IOS device to reload when processing IP version 6 (IPv6) packets over a Multiprotocol Label Switching (MPLS) domain.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPv6+over+MPLS+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d52.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software IPv6 Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d59.shtml</link>
      <description>Cisco IOS Software contains a vulnerability in the IP version 6 (IPv6) protocol stack implementation that could allow an unauthenticated, remote attacker to cause a reload of an affected device that has IPv6 enabled. The vulnerability may be triggered when the device processes a malformed IPv6 packet.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPv6+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d59.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d5a.shtml</link>
      <description>Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device or trigger memory leaks that may result in system instabilities. Affected devices would need to be configured to process SIP messages for these vulnerabilities to be exploitable.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Session+Initiation+Protocol+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d5a.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d57.shtml</link>
      <description>Cisco IOS Software contains two vulnerabilities related to Cisco IOS Intrusion Prevention System (IPS) and Cisco IOS Zone-Based Firewall features.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+IPS+and+Zone-Based+Firewall+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d57.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software Data-Link Switching Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4e.shtml</link>
      <description>Cisco IOS Software contains a memory leak vulnerability in the Data-Link Switching (DLSw) feature that could result in a device reload when processing crafted IP Protocol 91 packets.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Data-Link+Switching+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4e.shtml</guid>
    </item>
    <item>
      <title>Cisco IOS Software Network Address Translation Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4d.shtml</link>
      <description>The Cisco IOS Software network address translation (NAT) feature contains multiple denial of service (DoS) vulnerabilities in the translation of the following protocols: NetMeeting Directory (Lightweight Directory Access Protocol, LDAP); Session Initiation Protocol (Multiple vulnerabilities); H.323 protocol&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+IOS+Software+Network+Address+Translation+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d4d.shtml</guid>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Session Initiation Protocol Memory Leak Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d58.shtml</link>
      <description>Cisco Unified Communications Manager contains a memory leak vulnerability that could be triggered through the processing of malformed Session Initiation Protocol (SIP) messages. Exploitation of this vulnerability could cause an interruption of voice services. Cisco has released free software updates for supported Cisco Unified Communications Manager versions to address the vulnerability. A workaround exists for this SIP vulnerability. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Session+Initiation+Protocol+Memory+Leak+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d58.shtml</guid>
    </item>
    <item>
      <title>Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d47.shtml</link>
      <description>A denial of service (DoS) vulnerability exists in Jabber Extensible Communications Platform (Jabber XCP) and Cisco Unified Presence. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious XML to an affected server. Successful exploitation of this vulnerability could cause elevated memory and CPU utilization, resulting in memory exhaustion and process crashes. Repeated exploitation could result in a sustained DoS condition.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Jabber+Extensible+Communications+Platform+and+Cisco+Unified+Presence+XML+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95d47.shtml</guid>
    </item>
    <item>
      <title>CiscoWorks LAN Management Solution Remote Code Execution Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml</link>
      <description>Two vulnerabilities exist in CiscoWorks LAN Management Solution software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=CiscoWorks+LAN+Management+Solution+Remote+Code+Execution+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351f.shtml</guid>
    </item>
    <item>
      <title>Cisco Unified Service Monitor and Cisco Unified Operations Manager Remote Code Execution Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml</link>
      <description>Two vulnerabilities exist in Cisco Unified Service Monitor and Cisco Unified Operations Manager software that could allow an unauthenticated, remote attacker to execute arbitrary code on affected servers. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Service+Monitor+and+Cisco+Unified+Operations+Manager+Remote+Code+Execution+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9351e.shtml</guid>
    </item>
    <item>
      <title>Apache HTTPd Range Header Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml</link>
      <description>The Apache HTTPd server contains a denial of service vulnerability when it handles multiple, overlapping ranges. Multiple Cisco products may be affected by this vulnerability. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Apache+HTTPd+Range+Header+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml</guid>
    </item>
    <item>
      <title>Cisco Nexus 5000 and 3000 Series Switches Access Control List Bypass Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtml</link>
      <description>A vulnerability exists in Cisco Nexus 5000 and 3000 Series Switches that may allow traffic to bypass deny statements in access control lists (ACLs) that are configured on the device. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Nexus+5000+and+3000+Series+Switches+Access+Control+List+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b9250c.shtml</guid>
    </item>
    <item>
      <title>Denial of Service Vulnerability in Cisco TelePresence Codecs</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b91395.shtml</link>
      <description>Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs that are running software versions prior to TC4.0.0 or F9.1 contain a vulnerability that could allow an attacker to cause a denial of service.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerability+in+Cisco+TelePresence+Codecs" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b91395.shtml</guid>
    </item>
    <item>
      <title>Open Query Interface in Cisco Unified Communications Manager and Cisco Unified Presence Server</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml</link>
      <description>Cisco Unified Communications Manager (previously known as Cisco CallManager) and Cisco Unified Presence Server contain an open query interface that could allow an unauthenticated, remote attacker to disclose the contents of the underlying databases on affected product versions.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Open+Query+Interface+in+Cisco+Unified+Communications+Manager+and+Cisco+Unified+Presence+Server" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f532.shtml</guid>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Denial of Service Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f531.shtml</link>
      <description>Cisco Unified Communications Manager contains five (5) denial of service (DoS) vulnerabilities.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Unified+Communications+Manager+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f531.shtml</guid>
    </item>
    <item>
      <title>Denial of Service Vulnerabilities in Cisco Intercompany Media Engine</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f533.shtml</link>
      <description>Two denial of service (DoS) vulnerabilities exist in the Cisco Intercompany Media Engine. An unauthenticated attacker could exploit these vulnerabilities by sending crafted Service Advertisement Framework (SAF) packets to an affected device, which may cause the device to reload.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Denial+of+Service+Vulnerabilities+in+Cisco+Intercompany+Media+Engine" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8f533.shtml</guid>
    </item>
    <item>
      <title>Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8ad3f.shtml</link>
      <description>Cisco TelePresence Recording Server Software Release 1.7.2.0 includes a root administrator account that is enabled by default. Successful exploitation of the vulnerability could allow a remote attacker to use these default credentials to modify the system configuration and settings. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+TelePresence+Recording+Server+Default+Credentials+for+Root+Account+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8ad3f.shtml</guid>
    </item>
    <item>
      <title>Cisco SA 500 Series Security Appliances Web Management Interface Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml</link>
      <description>Cisco SA 500 Series Security Appliances are affected by two vulnerabilities on their web-based management interface. An attacker must have valid credentials for an affected device to exploit one vulnerability; exploitation of the other does not require authentication. Both vulnerabilities can be exploited over the network. Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are available.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+SA+500+Series+Security+Appliances+Web+Management+Interface+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b8915e.shtml</guid>
    </item>
    <item>
      <title>Cisco ASR 9000 Series Routers Line Card IP Version 4 Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b89155.shtml</link>
      <description>Cisco 9000 Series Aggregation Services Routers (ASR) running Cisco IOS XR Software version 4.1.0 contain a vulnerability that may cause a network processor in a line card to lock up while processing an IP version 4 (IPv4) packet. As a consequence of the network processor lockup, the line card that is processing the offending packet will automatically reload. Cisco has released a free software maintenance upgrade (SMU) to address this vulnerability. There are no workarounds for this vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+ASR+9000+Series+Routers+Line+Card+IP+Version+4+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b89155.shtml</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Cisco AnyConnect Secure Mobility Client</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80123.shtml</link>
      <description>The Cisco AnyConnect Secure Mobility Client, previously known as the Cisco AnyConnect VPN Client, is affected by multiple vulnerabilities. Arbitrary Program Execution Vulnerability Local Privilege Escalation Vulnerability Cisco has released free software updates that address these vulnerabilities. There are no workarounds for the vulnerabilities described in this advisory.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+AnyConnect+Secure+Mobility+Client" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80123.shtml</guid>
    </item>
    <item>
      <title>Cisco Content Services Gateway Denial of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b86503.shtml</link>
      <description>A denial of service (DoS) vulnerability exists in the Cisco Content Services Gateway - Second Generation, that runs on the Cisco Service and Application Module for IP (SAMI). An unauthenticated, remote attacker could exploit this vulnerability by sending a series of crafted ICMP packets to an affected device. Exploitation could cause the device to reload. There are no workarounds available to mitigate exploitation of this vulnerability other than blocking ICMP traffic destined to the affected device.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+Content+Services+Gateway+Denial+of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b86503.shtml</guid>
    </item>
    <item>
      <title>Cisco RVS4000 and WRVS4400N Web Management Interface Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f190.shtml</link>
      <description>Cisco RVS4000 4-port Gigabit Security Routers and Cisco WRVS4400N Wireless-N Gigabit Security Routers have several web interface vulnerabilities that can be exploited by a remote, unauthenticated user.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Cisco+RVS4000+and+WRVS4400N+Web+Management+Interface+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b7f190.shtml</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Cisco Unified IP Phones 7900 Series</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80111.shtml</link>
      <description>Cisco Unified IP Phones 7900 Series devices, also known as TNP phones, are affected by three vulnerabilities that could allow an attacker to elevate privileges, change phone configurations, disclose sensitive information, or load unsigned software. These three vulnerabilities are classified as two privilege escalation vulnerabilities and one signature bypass vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+Unified+IP+Phones+7900+Series" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80111.shtml</guid>
    </item>
    <item>
      <title>Default Credentials Vulnerability in Cisco Network Registrar</title>
      <link>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80121.shtml</link>
      <description>Cisco Network Registrar Software Releases prior to 7.2 contain a default password for the administrative account. During the initial installation, users are not forced to change this password, allowing it to persist after the installation. An attacker who is aware of this vulnerability could authenticate with administrative privileges and arbitrarily change the configuration of Cisco Network Registrar.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Advisories&amp;vs_p=Default+Credentials+Vulnerability+in+Cisco+Network+Registrar" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_advisory09186a0080b80121.shtml</guid>
    </item>
    <item>
      <title>Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_security_notice09186a00804a7912.html </link>
      <description>This Cisco Security Notice is being released in response to the Cisco VPN Concentrator Group Name Enumeration Vulnerability advisory published on June 20, 2005 by NTA Monitor at http://www.nta-monitor.com/news/vpn-flaws/cisco/VPN-Concentrator/index.htm.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+IPSec+VPN+Implementation+Group+Name+Enumeration+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_security_notice09186a00804a7912.html </guid>
    </item>
    <item>
      <title>Crafted DNS Packet Can Cause Denial Of Service</title>
      <link>http://www.cisco.com/en/US/products/sw/voicesw/ps5520/products_security_notice09186a0080477104.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Crafted+DNS+Packet+Can+Cause+Denial+Of+Service" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/voicesw/ps5520/products_security_notice09186a0080477104.html</guid>
    </item>
    <item>
      <title>Cisco IPsec VPN Implementation Group Password Usage Vulnerability</title>
      <link>http://www.cisco.com/en/US/tech/tk583/tk372/technologies_security_notice09186a0080215981.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+IPsec+VPN+Implementation+Group+Password+Usage+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk583/tk372/technologies_security_notice09186a0080215981.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco Clean Access Agent (Perfigo) Bypass</title>
      <link>http://www.cisco.com/en/US/products/ps6128/products_security_notice09186a00804fa82b.html </link>
      <description>This document is provided to simplify access to Cisco responses to possible product security vulnerability issues posted in public forums for Cisco customers. This does not imply that Cisco perceives each of these issues as an actual product security vulnerability. This notice is provided on an "as is" basis and does not imply any kind of guarantee or warranty. Your use of the information on the page or materials linked from this page are at your own risk. Cisco reserves the right to change or update this page without notice at any time.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+Clean+Access+Agent+(Perfigo)+Bypass" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/ps6128/products_security_notice09186a00804fa82b.html </guid>
    </item>
    <item>
      <title>CSS SSL Authentication Bypass</title>
      <link>http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_security_notice09186a0080512ff7.html</link>
      <description>The Cisco CSS 11500 Series Content Services Switches (CSS) running Secure Socket Layer (SSL) has a vulnerability that may allow a user to bypass SSL authentication and access protected content. Cisco has made free software available to address this vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=CSS+SSL+Authentication+Bypass" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_security_notice09186a0080512ff7.html</guid>
    </item>
    <item>
      <title>ZOTOB and WORM_RBOT.CBQ Mitigation Recommendations</title>
      <link>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00804f51de.html </link>
      <description>Cisco customers are currently experiencing attacks due to new worms and bots that are active on the Internet. The signature of these worms and bots appears as TCP traffic to port 445 as well as traffic to several secondary TCP ports depending on the variant of the worm. Affected customers have been experiencing high volumes of traffic from both internal and external systems. Symptoms on Cisco devices include, but are not limited to, high CPU and traffic drops on the input interfaces. This document focuses on both mitigation techniques and affected Cisco products that need software supplied by Cisco to patch properly.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=ZOTOB+and+WORM_RBOT.CBQ+Mitigation+Recommendations" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00804f51de.html </guid>
    </item>
    <item>
      <title>Response to Full-Disclosure - Potential Denial of Service Bug in Cisco Pix Firewall IOS 6.2.2 and 6.3.(3.102)</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a008024d9ca.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+Full-Disclosure+-+Potential+Denial+of+Service+Bug+in+Cisco+Pix+Firewall+IOS+6.2.2+and+6.3.(3.102)" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a008024d9ca.html</guid>
    </item>
    <item>
      <title>Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access</title>
      <link>http://www.cisco.com/warp/public/707/cisco-sn-20050608-8021x.shtml</link>
      <description>This Cisco Security Notice is being released in response to the Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access advisory published on June 8, 2005 by FishNet Security at http://www.fishnetsecurity.com/csirt/disclosure/cisco/. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+802.1x+Voice-Enabled+Interfaces+Allow+Anonymous+Voice+VLAN+Access" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/warp/public/707/cisco-sn-20050608-8021x.shtml</guid>
    </item>
    <item>
      <title>Vulnerability in a Variant of the TCP Timestamps Option</title>
      <link>http://www.cisco.com/en/US/products/hw/ps4159/ps2160/products_security_notice09186a008046f502.html </link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Vulnerability+in+a+Variant+of+the+TCP+Timestamps+Option" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/ps4159/ps2160/products_security_notice09186a008046f502.html </guid>
    </item>
    <item>
      <title>W32.BLASTER Worm Mitigation Recommendations</title>
      <link>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00801aedd6.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=W32.BLASTER+Worm+Mitigation+Recommendations" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00801aedd6.html</guid>
    </item>
    <item>
      <title>Cisco Internet Key Exchange Issue *Updated on 19-Jul-2004</title>
      <link>http://www.cisco.com/en/US/tech/tk583/tk372/technologies_security_notice09186a008016b57f.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+Internet+Key+Exchange+Issue+*Updated+on+19-Jul-2004" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk583/tk372/technologies_security_notice09186a008016b57f.html</guid>
    </item>
    <item>
      <title>Dictionary Attack on Cisco LEAP Vulnerability</title>
      <link>http://www.cisco.com/en/US/tech/tk722/tk809/technologies_security_notice09186a00801aa80f.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Dictionary+Attack+on+Cisco+LEAP+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk722/tk809/technologies_security_notice09186a00801aa80f.html</guid>
    </item>
    <item>
      <title>Alleged Bypassing Access Control List in Cisco IOS</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1824/products_security_notice09186a008022fa2c.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Alleged+Bypassing+Access+Control+List+in+Cisco+IOS" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1824/products_security_notice09186a008022fa2c.html</guid>
    </item>
    <item>
      <title>Exploit for Multiple Cisco Vulnerabilities *Updated on 07-May-2004 0930 PDT</title>
      <link>http://www.cisco.com/en/US/products/hw/routers/ps295/products_security_notice09186a008020ce3f.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Exploit+for+Multiple+Cisco+Vulnerabilities+*Updated+on+07-May-2004+0930+PDT" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/routers/ps295/products_security_notice09186a008020ce3f.html</guid>
    </item>
    <item>
      <title>Cisco Nachi Worm Mitigation Recommendations *Updated on 14-Oct-2003</title>
      <link>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00801b143a.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+Nachi+Worm+Mitigation+Recommendations+*Updated+on+14-Oct-2003" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_security_notice09186a00801b143a.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco 6509 Switch Telnet Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/hw/switches/ps708/products_security_notice09186a008024d9e6.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+6509+Switch+Telnet+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/switches/ps708/products_security_notice09186a008024d9e6.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - PIX Denial of Service</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a00802641d4.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+PIX+Denial+of+Service" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a00802641d4.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco CSS11000 Series DoS</title>
      <link>http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_security_notice09186a008024da37.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+CSS11000+Series+DoS" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/contnetw/ps792/products_security_notice09186a008024da37.html</guid>
    </item>
    <item>
      <title>Data Leak in UDP Echo Service</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a00801aa0cc.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Data+Leak+in+UDP+Echo+Service" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a00801aa0cc.html</guid>
    </item>
    <item>
      <title>Sending 2GB Data in GET Request Causes Buffer Overflow in Cisco IOS Software</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_security_notice09186a00801a97e1.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Sending+2GB+Data+in+GET+Request+Causes+Buffer+Overflow+in+Cisco+IOS+Software" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_security_notice09186a00801a97e1.html</guid>
    </item>
    <item>
      <title>Enumerating Locally Defined Users in Cisco IOS</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1824/products_security_notice09186a00801a6c01.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Enumerating+Locally+Defined+Users+in+Cisco+IOS" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1824/products_security_notice09186a00801a6c01.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco VPN Client can be used to Gain Local Administrator Rights (All Versions, Patched or Otherwise)</title>
      <link>http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_security_notice09186a008024da54.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+VPN+Client+can+be+used+to+Gain+Local+Administrator+Rights+(All+Versions,+Patched+or+Otherwise)" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_security_notice09186a008024da54.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco ACL Bug when using VPN Crypto Engine Accelerator, PPPoE Dialer or IP Route-Cache</title>
      <link>http://www.cisco.com/en/US/products/sw/secursw/ps2138/products_security_notice09186a008024daec.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+ACL+Bug+when+using+VPN+Crypto+Engine+Accelerator,+PPPoE+Dialer+or+IP+Route-Cache" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/secursw/ps2138/products_security_notice09186a008024daec.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco Systems VPN Client Allows Local Login with Elevated Privileges</title>
      <link>http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_security_notice09186a008024da6f.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+Systems+VPN+Client+Allows+Local+Login+with+Elevated+Privileges" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_security_notice09186a008024da6f.html</guid>
    </item>
    <item>
      <title>Cisco EIGRP Issue</title>
      <link>http://www.cisco.com/en/US/tech/tk365/technologies_security_notice09186a008011c5e1.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Cisco+EIGRP+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk365/technologies_security_notice09186a008011c5e1.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco as5350 Crashes with nmap Connect Scan</title>
      <link>http://www.cisco.com/en/US/products/hw/univgate/ps501/products_security_notice09186a008024dba2.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+as5350+Crashes+with+nmap+Connect+Scan" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/univgate/ps501/products_security_notice09186a008024dba2.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco SCA 11000 Series Secure Content Accelerator OpenSSL Issue</title>
      <link>http://www.cisco.com/en/US/products/hw/contnetw/ps2083/products_security_notice09186a008024dbaf.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+SCA+11000+Series+Secure+Content+Accelerator+OpenSSL+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/contnetw/ps2083/products_security_notice09186a008024dbaf.html</guid>
    </item>
    <item>
      <title>The Trivial Cisco IP Phones Compromise</title>
      <link>http://www.cisco.com/en/US/products/hw/phones/ps379/products_security_notice09186a00800e251b.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=The+Trivial+Cisco+IP+Phones+Compromise" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/phones/ps379/products_security_notice09186a00800e251b.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - VPN 3000 Gateway MTU Overflow</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_security_notice09186a008024dbbe.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+VPN+3000+Gateway+MTU+Overflow" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_security_notice09186a008024dbbe.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Weak Cisco PIX Enable Password Encryption Algorithm</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a00800a7ae6.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Weak+Cisco+PIX+Enable+Password+Encryption+Algorithm" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a00800a7ae6.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco Secure ACS Cross Site Scripting Issue</title>
      <link>http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_security_notice09186a008026434d.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+Secure+ACS+Cross+Site+Scripting+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_security_notice09186a008026434d.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco IOS Software - Three Possible DoS Attacks</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_security_notice09186a008026d9aa.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+IOS+Software+-+Three+Possible+DoS+Attacks" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_security_notice09186a008026d9aa.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Cisco IOS Software and ICMP Redirect Issue</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a008026433b.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Cisco+IOS+Software+and+ICMP+Redirect+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a008026433b.html</guid>
    </item>
    <item>
      <title>CDP Issue</title>
      <link>http://www.cisco.com/en/US/tech/tk962/technologies_security_notice09186a0080093ef0.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=CDP+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk962/technologies_security_notice09186a0080093ef0.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - HSRP Issues</title>
      <link>http://www.cisco.com/en/US/tech/tk648/tk362/technologies_security_notice09186a008026d960.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+HSRP+Issues" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk648/tk362/technologies_security_notice09186a008026d960.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - NTP Issue</title>
      <link>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a008026410b.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+NTP+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/sw/iosswrel/ps1818/products_security_notice09186a008026410b.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - PIX Security Notes</title>
      <link>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a0080265e37.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+PIX+Security+Notes" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_security_notice09186a0080265e37.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - Catalyst 3500 Issue</title>
      <link>http://www.cisco.com/en/US/products/hw/switches/ps637/products_security_notice09186a008026408a.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+Catalyst+3500+Issue" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/switches/ps637/products_security_notice09186a008026408a.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - TACACS  Vulnerability</title>
      <link>http://www.cisco.com/en/US/tech/tk59/technologies_security_notice09186a0080264060.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+TACACS++Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/tech/tk59/technologies_security_notice09186a0080264060.html</guid>
    </item>
    <item>
      <title>Response to BugTraq - show Command Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/hw/routers/ps274/products_security_notice09186a0080264595.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Notices&amp;vs_p=Response+to+BugTraq+-+show+Command+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/hw/routers/ps274/products_security_notice09186a0080264595.html</guid>
    </item>
    <item>
      <title>Attention: New Cisco Security Response RSS Feed Locations</title>
      <link>http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityResponse.xml</link>
      <description>Effective October 18, 2011, Cisco has replaced the existing RSS feeds for Cisco Security Responses. The new RSS feeds for Cisco Security Responses are available at http://tools.cisco.com/security/center/psirtrss10/CiscoSecurityResponse.xml and  http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityResponse.xml.  The existing RSS feeds will continue to function until November 19, 2011.  They will not receive updates after this date.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Attention:+New+Cisco+Security+Response+RSS+Feed+Locations" border="0" height="0" width="0" /&gt;</description>
      <guid>http://tools.cisco.com/security/center/psirtrss20/CiscoSecurityResponse.xml</guid>
    </item>
    <item>
      <title>Infected Cisco Information Packet and Warranty CDs</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b8b122.html</link>
      <description>In the period of December 2010 until August 2011, Cisco shipped warranty CDs that contain a reference to a third-party website known to be a malware repository. When the CD is opened with a web browser, it automatically and without warning accesses this third-party website. Additionally, on computers where the operating system is configured to automatically open inserted media, the computer's default web browser will access the third-party site when the CD is inserted, without requiring any further action by the user.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Infected+Cisco+Information+Packet+and+Warranty+CDs" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b8b122.html</guid>
    </item>
    <item>
      <title>Cisco IOS Software Denial of Service Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b7b502.html</link>
      <description>This is the Cisco PSIRT (Product Security Incident Response Team) response to two postings on BugTraq by NCNIPC (China) regarding reported vulnerabilities in Cisco IOS Software.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Software+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b7b502.html</guid>
    </item>
    <item>
      <title>Rootkits on Cisco IOS Devices</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080997783.html</link>
      <description>Updated Cisco IOS hashes file is available. This is the Cisco PSIRT response to an issue to be disclosed at the EUSecWest security conference on May 22nd, 2008 by Mr. Sebastian Muniz of Core Security Technologies. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Rootkits+on+Cisco+IOS+Devices" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080997783.html</guid>
    </item>
    <item>
      <title>Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b5992c.html</link>
      <description>This Cisco Security Response is an updated version of an original Cisco Security Notice, in response to the Cisco VPN Concentrator Group Name Enumeration Vulnerability advisory published on June 20, 2005, by NTA Monitor. Update to summary.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IPSec+VPN+Implementation+Group+Name+Enumeration+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b5992c.html</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Cisco Unified Videoconferencing Products</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html</link>
      <description>This is the Cisco Product Security Incident Response Team (PSIRT) response to a posting entitled "Cisco Unified Videoconferencing multiple vulnerabilities" by Florent Daigniere of Matta Consulting regarding vulnerabilities in the Cisco Unified Videoconferencing (Cisco UVC) 5100 series products. Several of the vulnerabilities also impact Cisco Unified Videoconferencing 5200 and 3500 Series Products. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Multiple+Vulnerabilities+in+Cisco+Unified+Videoconferencing+Products" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html</guid>
    </item>
    <item>
      <title>Cisco Unified MeetingPlace XSS Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html</link>
      <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Roger Jefferiss and Rob Pope of SecureTest Ltd, UK regarding cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace Web Conferencing.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+XSS+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008089969e.html</guid>
    </item>
    <item>
      <title>Cisco Unified MeetingPlace XSS Vulnerability (November 2007)</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808f0b8f.html</link>
      <description>This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by Joren McReynolds regarding a cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace Web Conferencing.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+XSS+Vulnerability+(November+2007)" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808f0b8f.html</guid>
    </item>
    <item>
      <title>Cisco IronPort Desktop Flag Plug-in for Outlook Information Disclosure</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080b2c505.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IronPort+Desktop+Flag+Plug-in+for+Outlook+Information+Disclosure" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080b2c505.html</guid>
    </item>
    <item>
      <title>Unmatched Request Discloses Client Internal IP Address</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080af8965.html</link>
      <description>This is the Cisco PSIRT response to the statements made by Alejandro Hernandez H. in his advisory: "Cisco ACE XML Gateway &lt;= 6.0 Internal IP disclosure". &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Unmatched+Request+Discloses+Client+Internal+IP+Address" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080af8965.html</guid>
    </item>
    <item>
      <title>Cisco Response to Outpost24 TCP State Table Manipulation Denial of Service Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html </link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Response+to+Outpost24+TCP+State+Table+Manipulation+Denial+of+Service+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a15120.html </guid>
    </item>
    <item>
      <title>Cisco IOS Cross-Site Scripting Vulnerabilities</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.html</link>
      <description>Two separate Cisco IOS Hypertext Transfer Protocol (HTTP) cross-site scripting (XSS) vulnerabilities have been reported to Cisco by two independent researchers.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Cross-Site+Scripting+Vulnerabilities" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a5c501.html</guid>
    </item>
    <item>
      <title>Cisco IP Phone 7940/7960 SIP INVITE Denial of Service</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html</link>
      <description>This is Cisco PSIRT's response to the statements made by Radu State in his message titled: CISCO Phone 7940 DOS vulnerability posted on 2007 March 20 0630 UTC (GMT). The original email is available at:http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/053070.html Cisco has confirmed the findings of the statements made. Cisco IP Phone 7940/7960 SIP firmware version 7.4(0) is vulnerable to the denial of service. Firmware version 8.6(0) is not vulnerable to this issue. The latest firmware images for Cisco IP 7940/7960 phones can be obtained here: http://www.cisco.com/cgi-bin/tablebuild.pl/sip-ip-phone7960 We would like to thank Radu State, Humberto J. Abdelnur and Olivier Festor of the Madynes research team at INRIA for reporting these issues to Cisco Systems. We greatly appreciate the opportunity to work with researchers on security vulnerabilities, and welcome the opportunity to review and assist in product reports.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IP+Phone+7940/7960+SIP+INVITE+Denial+of+Service" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808075ad.html</guid>
    </item>
    <item>
      <title>Cisco Unified MeetingPlace Stored Cross-Site Scripting Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a7bc61.html</link>
      <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by the National Australia Bank Security Assurance team regarding a cross-site scripting vulnerability in Cisco Unified MeetingPlace Web Conferencing. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+MeetingPlace+Stored+Cross-Site+Scripting+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a7bc61.html</guid>
    </item>
    <item>
      <title>MD5 Hashes May Allow for Certificate Spoofing</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html</link>
      <description>This is the Cisco response to research done by Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, and Benne de Weger pertaining to MD5 collisions in certificates issued by vulnerable certificate authorities. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=MD5+Hashes+May+Allow+for+Certificate+Spoofing" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html</guid>
    </item>
    <item>
      <title>Cisco Response to TKIP Encryption Weakness</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a30036.html</link>
      <description>&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Response+to+TKIP+Encryption+Weakness" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a30036.html</guid>
    </item>
    <item>
      <title>Cisco VLAN Trunking Protocol Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a231cf.html</link>
      <description>This is the Cisco response to research done by 'showrun.lee' pertaining to a crafted VTP packet denial of service vulnerability.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+VLAN+Trunking+Protocol+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a231cf.html</guid>
    </item>
    <item>
      <title>VoIPshield Reported Vulnerabilities in Cisco Unity Server</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.html</link>
      <description>This is the Cisco PSIRT response to the vulnerabilities in Cisco Unity by VoIPshield, in their recent advisories (VSRCS-2008-008 to VSRCS-2008-012). The original advisories are available at: www.voipshield.com .&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=VoIPshield+Reported+Vulnerabilities+in+Cisco+Unity+Server" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080a0d861.html</guid>
    </item>
    <item>
      <title>Cisco Secure ACS Denial Of Service Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00809f140b.html</link>
      <description>This is the Cisco PSIRT response to the statements made by Laurent Butti and Gabriel Campana of Orange Labs / France Telecom Group, in their advisory: "Cisco Secure ACS EAP Parsing Vulnerability". The original advisory is available at: http://www.securityfocus.com/archive/1/495937/30/0/threaded &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Secure+ACS+Denial+Of+Service+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00809f140b.html</guid>
    </item>
    <item>
      <title>Internet Key Exchange Resource Exhaustion Attack</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00806f33d4.html</link>
      <description>This is a Cisco PSIRT response to an advisory published by an unaffiliated third party, Roy Hills, of NTA Monitor Ltd posted as of July 26, 2006 at http://www.nta-monitor.com/posts/2006/07/cisco-concentrator-dos.html, and entitled: Cisco VPN Concentrator IKE resource exhaustion DoS.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Internet+Key+Exchange+Resource+Exhaustion+Attack" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00806f33d4.html</guid>
    </item>
    <item>
      <title>Vulnerability in Java Secure Socket Extension</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008088bd19.html</link>
      <description>This is the Cisco PSIRT response to the vulnerability in Java Secure Socket Extension (JSSE) disclosed by Sun Microsystems on July 10, 2007, the details of which are available at http://sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Vulnerability+in+Java+Secure+Socket+Extension" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008088bd19.html</guid>
    </item>
    <item>
      <title>Wide Area Application Services (WAAS) Common UNIX Printing System (CUPS) Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.html</link>
      <description>This is the Cisco PSIRT response to a security advisory regarding a vulnerability in Common UNIX Printing System (CUPS). The CUPS security advisory can be found at http://www.cups.org/str.php?L2561.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Wide+Area+Application+Services+(WAAS)+Common+UNIX+Printing+System+(CUPS)+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00809a1f11.html</guid>
    </item>
    <item>
      <title>Catalyst 6500 and Cisco 7600 Series Devices Accessible via Loopback Address</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808ca009.html </link>
      <description>This document is the Cisco PSIRT response to an issue regarding Cisco Catalyst 6500 and Cisco 7600 series devices that was discovered and reported to Cisco by Lee E. Rian .&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Catalyst+6500+and+Cisco+7600+Series+Devices+Accessible+via+Loopback+Address" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808ca009.html </guid>
    </item>
    <item>
      <title>CiscoWorks Server XSS Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008090a498.html</link>
      <description>This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by David Lewis of Liquidmatrix.org regarding a cross-site scripting (XSS) vulnerability in CiscoWorks Server login page.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=CiscoWorks+Server+XSS+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008090a498.html</guid>
    </item>
    <item>
      <title>Extensible Authentication Protocol Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808de8bb.html</link>
      <description>This is the Cisco PSIRT response to a presentation that was delivered by Laurent Butti, Julien Tinnhs and Franck Veysset of France Telecom Group at Hack.lu on October 19th, 2007.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Extensible+Authentication+Protocol+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808de8bb.html</guid>
    </item>
    <item>
      <title>Cisco Unified IP Phone Remote Eavesdropping</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html</link>
      <description>This is the Cisco PSIRT response to a presentation given at the Hack.Lu 2007 security conference by Joffery Czarny of Telindus regarding a technique to remotely eavesdrop using Cisco Unified IP Phones.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Unified+IP+Phone+Remote+Eavesdropping" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080903a6d.html</guid>
    </item>
    <item>
      <title>Cisco IOS Line Printer Daemon (LPD) Protocol Stack Overflow</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.html</link>
      <description>This is the Cisco Product Security Incident Response Team (PSIRT) response to an issue discovered and reported to Cisco by Andy Davis from IRM, Plc. regarding a stack overflow in the Cisco IOS Line Printer Daemon (LPD) Protocol feature. The original post is available at the following link:&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Line+Printer+Daemon+(LPD)+Protocol+Stack+Overflow" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808d72e3.html</guid>
    </item>
    <item>
      <title>Cisco IOS Reload on Regular Expression Processing</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html</link>
      <description>This is the Cisco Product Security Incident Response Team (PSIRT) response to a vulnerability that was reported on the Cisco NSP mailing list on August 17, 2007 regarding the crash and reload of devices running Cisco IOS. after executing a command that uses, either directly or indirectly, a regular expression.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+IOS+Reload+on+Regular+Expression+Processing" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808bb91c.html</guid>
    </item>
    <item>
      <title>VTY Authentication Bypass Vulnerability</title>
      <link>http://www.cisco.com/warp/customer/707/cisco-sr-20070829-vty.shtml</link>
      <description>This is the Cisco PSIRT response to the NileSOFT Security Advisory 	 entitled "Bypass Authentication Vulnerability on Cisco Catalyst 3750 12.2(25)" posted on August 29th, 2007, at 1800 UTC (GMT).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=VTY+Authentication+Bypass+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/warp/customer/707/cisco-sr-20070829-vty.shtml</guid>
    </item>
    <item>
      <title>Multiple SIP Vulnerabilities in the Cisco 7960 IP Phones</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808a6693.html</link>
      <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Radu State, Humberto J. Abdelnur and Oliver Festor regarding two Session Initiation Protocol (SIP) vulnerabilities in the Cisco 7940/7960 IP Phones. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Multiple+SIP+Vulnerabilities+in+the+Cisco+7960+IP+Phones" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808a6693.html</guid>
    </item>
    <item>
      <title>Multiple Vulnerabilities in OpenSSL Library</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008077af1b.html</link>
      <description>This is the Cisco PSIRT response to the multiple security advisories published by The OpenSSL Project. The vulnerabilities are as follows: RSA Signature Forgery (CVE-2006-4339), described in http://www.openssl.org/news/secadv_20060905.txt ASN.1 Denial of Service Attacks (CVE-2006-2937, CVE-2006-2940), described in http://www.openssl.org/news/secadv_20060928.txt SSL_get_shared_ciphers() buffer overflow (CVE-2006-3738), also in http://www.openssl.org/news/secadv_20060928.txt SSLv2 Client Crash (CVE-2006-4343), also in http://www.openssl.org/news/secadv_20060928.txt&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Multiple+Vulnerabilities+in+OpenSSL+Library" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008077af1b.html</guid>
    </item>
    <item>
      <title>Cisco Trust Agent - Mac OS X Privilege Escalation Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html</link>
      <description>This is the Cisco PSIRT response to an issue discovered and reported to Cisco by Adam Blake of Deloitte, UK regarding a vulnerability in Cisco Trust Agent (CTA) installations on Mac OS X. The original report is available at the following link: http://www.securityfocus.com/archive/1/471041/30/0/flat.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+Trust+Agent+-+Mac+OS+X+Privilege+Escalation+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008085d645.html</guid>
    </item>
    <item>
      <title>Cisco CallManager Input Validation Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080849272.html</link>
      <description>This is Cisco PSIRT's response to the statements made by Marc Ruef and Stefan Friedi from scip AG in their message "Cisco CallManager 4.1 Input Validation Vulnerability," posted on 2007 May 23 at 1600 UTC (GMT).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+CallManager+Input+Validation+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080849272.html</guid>
    </item>
    <item>
      <title>HTTP Full-Width and Half-Width Unicode Encoding Evasion</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008083f82e.html</link>
      <description>The U.S. Computer Emergency Response Team (US-CERT) has reported a network evasion technique using full-width and half-width unicode characters that affects several Cisco products. The US-CERT advisory is available at the following link: http://www.kb.cert.org/vuls/id/739224 &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=HTTP+Full-Width+and+Half-Width+Unicode+Encoding+Evasion" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008083f82e.html</guid>
    </item>
    <item>
      <title>DHCP Relay Agent Vulnerability in Cisco PIX and ASA Appliances</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080833172.html</link>
      <description>This is a Cisco response to a CERT/CC advisory posted on May 2, 2007, entitled "Cisco ASA fails to properly process DHCP relay packets". &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=DHCP+Relay+Agent+Vulnerability+in+Cisco+PIX+and+ASA+Appliances" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080833172.html</guid>
    </item>
    <item>
      <title>PHP HTML Entity Encoder Heap Overflow Vulnerability in Multiple Web-Based Management Interfaces</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.html</link>
      <description>This is a response to a Hardened-PHP Project advisory posted on November 3, 2006, entitled "PHP HTML Entity Encoder Heap Overflow Vulnerability."&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=PHP+HTML+Entity+Encoder+Heap+Overflow+Vulnerability+in+Multiple+Web-Based+Management+Interfaces" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a008082c4fe.html</guid>
    </item>
    <item>
      <title>Cross-Site Scripting Vulnerability in Online Help System</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html</link>
      <description>A cross-site scripting (XSS) vulnerability in the online help system distributed with several Cisco products has been independently reported to Cisco by Erwin Paternotte from Fox-IT and by Cassio Goldschmidt. The vulnerability would allow an attacker to execute arbitrary scripting code in a user's web browser if the attacker is successful in enticing the user to follow a specially crafted, malicious URL.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cross-Site+Scripting+Vulnerability+in+Online+Help+System" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a0080803fe4.html</guid>
    </item>
    <item>
      <title>NACATTACK Presentation</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html</link>
      <description>This is Cisco PSIRT's response to the "NACATTACK" presentation by Dror-John Roecher and Michael Thumann, presented at Blackhat Europe on March 30th, 2007.&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=NACATTACK+Presentation" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00808110da.html</guid>
    </item>
    <item>
      <title>Cisco VTP Vulnerability</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00807d1a81.html</link>
      <description>An issue has been reported to the Cisco PSIRT involving malformed VLAN Trunking Protocol (VTP) packets. This attack may cause the target device to reload, causing a Denial of Service (DoS).&lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Cisco+VTP+Vulnerability" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00807d1a81.html</guid>
    </item>
    <item>
      <title>Potential Exploitation of Default Administrative Credentials</title>
      <link>http://www.cisco.com/en/US/products/products_security_response09186a00807e3946.html</link>
      <description>This is a response to a Symantec published research paper posted on their website at http://www.symantec.com/enterprise/security_response/weblog/2007/02/driveby_pharming_how_clicking_1.html and http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf, and entitled 'Drive-by Pharming'. In particular, this response focuses on the information in the Symantec paper, as relevant to certain of Cisco's non-consumer products. These products are specified in the 'Cisco Routers Impacted' section below. &lt;img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&amp;vs_f=Cisco+Security+Responses&amp;vs_p=Potential+Exploitation+of+Default+Administrative+Credentials" border="0" height="0" width="0" /&gt;</description>
      <guid>http://www.cisco.com/en/US/products/products_security_response09186a00807e3946.html</guid>
    </item>
  </channel>
</rss>

