Cisco patches nine Crosswork and Secure Workload flaws, five rated a perfect ten
Cisco released fixes for nine vulnerabilities across its Crosswork network-automation platforms and Secure Workload software, five of them rated 10.0. Four affect Crosswork Data Gateway, Network Controller, and Planning regardless of configuration, and include a SQL injection flaw, a missing-authentication flaw, and external control of the file system, each scored 10.0, plus an insufficiently protected credentials issue at 9.9. Five more affect Secure Workload in both cloud and on-premises deployments, led by a 10.0 improper access control flaw and a 9.9 command-injection flaw. Cisco found them in internal testing using AI models and says none are exploited yet, but there are no workarounds, so patching is the only fix.
- Check
- Upgrade Crosswork to 7.2.1-SP and Secure Workload to 3.10.9.1 or 4.0.4.16, and note that Secure Workload cloud tenants must still upgrade agent and connector software themselves.
- Affected
- Organizations running Cisco Crosswork 7.2.1 or earlier, or Secure Workload 3.10 or 4.0 branches; multiple 10.0 flaws allow SQL injection, authentication bypass, file-system control, and command injection, with no workarounds.
- Fix
- Apply the fixed releases promptly since there are no workarounds, prioritize internet-reachable instances, and for Secure Workload cloud deployments confirm agent and connector components are upgraded, not just Cisco's cluster.