← All articles

Cisco patches nine Crosswork and Secure Workload flaws, five rated a perfect ten

Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.

Check
Upgrade Crosswork to 7.2.1-SP and Secure Workload to 3.10.9.1 or 4.0.4.16, and note that Secure Workload cloud tenants must still upgrade agent and connector software themselves.
Affected
Organizations running Cisco Crosswork 7.2.1 or earlier, or Secure Workload 3.10 or 4.0 branches; multiple 10.0 flaws allow SQL injection, authentication bypass, file-system control, and command injection, with no workarounds.
Fix
Apply the fixed releases promptly since there are no workarounds, prioritize internet-reachable instances, and for Secure Workload cloud deployments confirm agent and connector components are upgraded, not just Cisco's cluster.