{"id":35157,"date":"2020-05-25T09:31:44","date_gmt":"2020-05-25T09:31:44","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/"},"modified":"2020-05-25T09:31:44","modified_gmt":"2020-05-25T09:31:44","slug":"pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/","title":{"rendered":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2015\/08\/07\/rsa_callcenter_photo_rsa.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><strong class=\"trailer\">Roundup<\/strong> It&#8217;s once again time to catch up on the latest happenings from the world of infosec.<\/p>\n<h3 class=\"crosshead\"><span>Cisco emits critical fix in latest patch bundle<\/span><\/h3>\n<p>We have a bunch of new <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/tools.cisco.com\/security\/center\/publicationListing.x\">security patches<\/a> from Switchzilla, including one for a critical hole in its call-center software.<\/p>\n<p><a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/tools.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-uccx-rce-GMSC6RKN\">CVE-2020-3280<\/a> is a remote-code-execution vulnerability in the Java remote management interface for Unified Contact Center Express.<\/p>\n<p>An unauthenticated, remote attacker able to exploit the flaw by supplying a malformed Java object (this is possible through various user input fields) can gain get root control over the management system. Admins are being advised to update Unified CCX as soon as possible.<\/p>\n<h3 class=\"crosshead\"><span>Zoom hatches crypto plan, wants your help<\/span><\/h3>\n<p>After addressing complaints about its lax security and privacy practices, and <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2020\/04\/20\/security_roundup_190420\/\" rel=\"noopener noreferrer\">reaching out<\/a> to the industry for help, Zoom has put forward a plan to implement what it says is end-to-end encryption on its video calls.<\/p>\n<p>The online conferencing giant, suddenly one of the most vital service providers on the planet thanks to the coronavirus lockdowns, has uploaded a <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/github.com\/zoom\/zoom-e2e-whitepaper\/blob\/master\/zoom_e2e.pdf\">whitepaper<\/a> [PDF] describing how it will improve its encryption to thwart eavesdroppers.<\/p>\n<p>The aim here, says Zoom, is to gradually overhaul its call encryption and security features, starting with public key management and then moving on to addressing identity management, transparency, and eventually adding real-time security protections.<\/p>\n<p>These plans, however, are not yet set in stone, and Zoom has invited netizens to weigh in on its <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/github.com\/zoom\/zoom-e2e-whitepaper\">GitHub page<\/a> with their thoughts on the matter. An open comment period on the paper is being held from May 22 through June 5.<\/p>\n<h3 class=\"crosshead\"><span>Talos warns of WolfRAT<\/span><\/h3>\n<p>Cisco&#8217;s Talos team has taken a detailed look at a spyware operation sounds like a high school garage band: <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/blog.talosintelligence.com\/2020\/05\/the-wolf-is-back.html\">WolfRAT<\/a>.<\/p>\n<p>The malware has so far been concentrated in Thailand and spreads through fake versions of popular Android apps in third-party markets. The software nasty is believed to be related to the DenDroid malware, though Talos is not particularly impressed with the quality of build.<\/p>\n<p>&#8220;This malware is simplistic in comparison to some modern-day Android malware,&#8221; the researchers noted. &#8220;The best example of that is that it doesn&#8217;t take advantage of the accessibility framework, collecting information on non-rooted devices.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Hackers try to exploit flaws in Sophos firewall product<\/span><\/h3>\n<p>Sophos says a set of <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2020\/04\/26\/security_roundup_240420\/\" rel=\"noopener noreferrer\">hastily pushed hotfixes<\/a> recently helped to avert disaster.<\/p>\n<p>The corp <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/news.sophos.com\/en-us\/2020\/05\/21\/asnarok2\/\">reported<\/a> an SQL injection vulnerability in its XG Firewall was being targeted by an unspecified ransomware crew, though thanks to the emergency updates, the attempts to exploit the bug were unsuccessful, apparently.<\/p>\n<p>As the bug is still under active attack, any admins who haven&#8217;t applied the software update would be well-advised to make sure they are running the most current version of XG Firewall to keep their networks safe.<\/p>\n<h3 class=\"crosshead\"><span>Microsoft pushes Edge Chromium fix<\/span><\/h3>\n<p>A security fix has been issued for Chromium, which means that Microsoft has to follow suit with an update for its Chromium-based Edge browser.<\/p>\n<p>Redmond <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1195\">reported<\/a> that CVE-2020-1195 is an elevation of privilege hole that can be exploited when the Feedback extension receives malformed input from the user.<\/p>\n<p>&#8220;The vulnerability by itself does not allow arbitrary code to run,&#8221; notes Microsoft.<\/p>\n<p>&#8220;However, this vulnerability could be used in conjunction with one or more vulnerabilities (for example a remote code execution vulnerability and another elevation of privilege vulnerability) to take advantage of the elevated privileges when running.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Hackers tout 40m Wishbone credentials<\/span><\/h3>\n<p>Anyone running Wishbone, a mobile app that lets users vote on stuff, will want to change their password and any other services where that password was reused.<\/p>\n<p>This is because hackers have <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hacker-shares-40-million-wishbone-user-records-for-free\/\">stolen and leaked the details<\/a> on some 40 million accounts from the app, including hashed passwords, mobile numbers, date of birth and profile images.<\/p>\n<h3 class=\"crosshead\"><span>Signal cleans up &#8216;coarse tracking&#8217; vulnerability<\/span><\/h3>\n<p>Tenable laid claim to the discovery and reporting of a <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/medium.com\/tenable-techblog\/turning-signal-app-into-a-coarse-tracking-device-643eb4298447\">coarse tracking flaw<\/a> in the Signal secure phone app.<\/p>\n<p>The bug, which has already been fixed, would have potentially allowed an attacker to observe the location of a target&#8217;s DNS server via webRTC.<\/p>\n<p>Here&#8217;s where we should emphasize that the word tracking is pretty generous here, because Tenable estimates that the location info is only accurate to a radius of around 400 miles. So in theory, it could have exposed the person&#8217;s country, but not a lot else.<\/p>\n<p>Either way, just make sure you&#8217;re running the latest version of Signal and everything should be fine.<\/p>\n<h3 class=\"crosshead\"><span>macOS Notification Center holds a surprising amount of info<\/span><\/h3>\n<p>Kinga Kieczkowska <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/kieczkowska.com\/2020\/05\/20\/macos-notifications-forensics\/\">dug into<\/a> the inner-workings of the Mac&#8217;s notification hub (used by various apps to produce pop-up alerts) and found that it logs an unexpected amount of information.<\/p>\n<p>What Kieczkowska revealed was a sizable database that the hub maintains with things like location history, images and message content, even the contents of Twitter private messages (should that notification option be turned on). While this isn&#8217;t a huge security risk (it&#8217;s all stored locally, after all) it is definitely an eye-opener and the full report is worth a read.<\/p>\n<h3 class=\"crosshead\"><span>Tapplock settles with FTC<\/span><\/h3>\n<p>When we last heard from Tapplock, the Canadian smart lock company with under fire from the FTC after it <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2020\/04\/06\/tapplock_ftc\/\" rel=\"noopener noreferrer\">was found that<\/a> the security of its products, physical and online, was woeful.<\/p>\n<p>Now, the Indiegogo darling will be placing itself under the watchful eye of auditors as it <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2020\/05\/ftc-gives-final-approval-settlement-smart-lock-maker\">has agreed<\/a> to a settlement deal with the US trade body.<\/p>\n<p>There&#8217;s no money involved in the settlement, but that&#8217;s pretty standard with these sort of deals. When the FTC makes a settlement like this with a first-time offender, they&#8217;re really just hoping the company is scared straight and will stop doing whatever it was that got them in trouble.<\/p>\n<p>Should Tapplock be found to be neglecting its security, this deal pretty much puts it at the mercy of the FTC as far as penalties.<\/p>\n<h3 class=\"crosshead\"><span>Hacker &#8216;Sanix&#8217; arrested with massive data cache<\/span><\/h3>\n<p>A suspected hacker has been arrested in Ukraine, though the <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/ssu.gov.ua\/ua\/news\/1\/category\/2\/view\/\">plod<\/a> did not give a name nor any info on the individual cuffed. They did say the person is thought to be Sanix, the notorious hacker who last year was offering a collection of more than 770 million purloined email addresses and millions of credentials.<\/p>\n<h3 class=\"crosshead\"><span>Adobe Character Animator draws up fix for critical bug<\/span><\/h3>\n<p>Adobe posted a series of security updates recently for some of its more obscure media tools. While most were relatively minor information disclosure bugs, one was a bit more serious.<\/p>\n<p>Those who use Adobe Character Animator will want to update their software to protect against <a target=\"_blank\" rel=\"nofollow noopener noreferrer\" href=\"https:\/\/helpx.adobe.com\/security\/products\/character_animator\/apsb20-25.html\">CVE-2020-9586<\/a>, an arbitrary code execution flaw. Users can update Creative Cloud to get the fix, while admins can push it via Admin Console.<\/p>\n<p>While Character Animator doesn&#8217;t have the reach of Flash Player or Reader, and is highly unlikely to be targeted, it&#8217;s worth keeping your software up to date, and any code execution flaw is one worth fixing ASAP. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1942\/-8722\/ransomware-has-gone-nuclear?td=wptl1942\">Webcast: Ransomware has gone nuclear<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/go.theregister.co.uk\/feed\/www.theregister.co.uk\/2020\/05\/25\/security_roundup_220520\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This and more bits and bytes from infosec world Roundup\u00a0 It&#8217;s once again time to catch up on the latest happenings from the world of infosec.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":35158,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-35157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-25T09:31:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"648\" \/>\n\t<meta property=\"og:image:height\" content=\"486\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs\",\"datePublished\":\"2020-05-25T09:31:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/\"},\"wordCount\":1178,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/\",\"name\":\"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg\",\"datePublished\":\"2020-05-25T09:31:44+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/05\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg\",\"width\":648,\"height\":486},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/","og_locale":"en_US","og_type":"article","og_title":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-05-25T09:31:44+00:00","og_image":[{"width":648,"height":486,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs","datePublished":"2020-05-25T09:31:44+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/"},"wordCount":1178,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/","url":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/","name":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg","datePublished":"2020-05-25T09:31:44+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/05\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs.jpg","width":648,"height":486},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/pre-authentication-remote-root-hole-in-call-center-software-thanks-cisco-just-what-a-long-weekend-needs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Pre-authentication, remote root hole in call-center software? Thanks, Cisco. Just what a long weekend needs"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=35157"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/35157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/35158"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=35157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=35157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=35157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}