Dell, EMC, Dell Technologies, Cisco,

Showing posts with label Webex. Show all posts
Showing posts with label Webex. Show all posts

Saturday, April 21, 2018

Cisco plugs critical hole in WebEx, users urged to upgrade ASAP

@Cisco has fixed a critical vulnerability in its @WebEx #videoconferencing software that could be exploited to compromise meeting attendees’ systems by simply opening a booby-trapped Flash file shared in a meeting. About the vulnerability (CVE-2018-0112) The flaw is due to insufficient input validation by the Cisco WebEx clients, and affects Cisco WebEx Business Suite clients, Cisco WebEx Meetings, and Cisco WebEx Meetings Server. (The Cisco WebEx Business Suite (WBS) meeting services and Cisco WebEx Meetings are a hosted multimedia conferencing solution that is managed and maintained by Cisco WebEx. The Cisco WebEx Meetings Server is a multimedia conferencing solution that customers can host in their private clouds. Customers download the WebEx client application to attend meetings on the various Cisco WebEx Centers.) “To exploit this vulnerability, the client application would require a meeting attendee to open a malicious Flash file. An attacker may be able to accomplish this exploit by providing the malicious .swf file directly to users via the file-sharing capabilities of the client,” Cisco explained in an advisory published on Wednesday. The good news is that it is not currently being exploited in the wild: it was discovered and reported to Cisco by Alexandros Zacharis, an officer in the European Union Agency for Network and Information Security (ENISA). There are no workarounds for the flaw, so users should either upgrade their software to the latest releases or remove it from their systems altogether. Other vulnerabilities fixed Cisco has also released on Wednesday a number of security updates for several of its security appliances and other software. Among the holes plugged is one affecting the company’s unified infrastructure management solution that simplifies data center operations. “A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal and perform any permitted operations on any virtual machine,” the company explained. “The vulnerability is due to improper user authentication checks. An attacker could exploit this vulnerability by logging in to the UCS Director with a modified username and valid password. A successful exploit could allow the attacker to gain visibility into and perform actions against all virtual machines in the UCS Director end-user portal of the affected system.”

https://www.helpnetsecurity.com/2018/04/19/cisco-webex-cve-2018-0112/

Tuesday, January 24, 2017

This ex-Cisco exec's startup kicked off 2017 by getting a $1 billion valuation that’s putting it in the spotlight

The new year has already been good to videoconferencing startup #Zoom, a fast-growing competitor to #Cisco 's ubiquitous #WebEx. Just last week, the San Jose-based company raised $100 million at a $1 billion valuation in a round led by legendary investment firm Sequoia Capital, making it Silicon Valley's newest "unicorn." At the same time, Zoom disclosed it had 450,000 customers, including Uber and SolarCity, and that it finished 2016 with two cash flow positive quarters, back to back. Days later, a report from fellow enterprise unicorn Okta indicated that in 2016, Zoom was the fastest-growing app among its subscribers — a distinction previously held by $3.8 Silicon Valley golden child Slack. In other words, if you haven't heard of Zoom yet, you probably will soon. Business Insider sat down with Zoom CEO Eric S. Yuan (via a Zoom videoconference, naturally) to talk about where his startup came from, and where it's going next.

http://www.businessinsider.com/zoom-ceo-eric-yuan-interview-2017-1