Skip to main content

Cisco Prime Home is vulnerable to attack, and your ISP needs to update it

1129714 autosave v1 hackers22
Shutterstock
As we connect more and more devices to the internet, we create more and more potential security vulnerabilities. While we’re usually aware of the gadgets we use every day — our PCs, smartphones, and tablets — we might now always think about just how secure are all of our other connected devices like networked cameras, cable boxes, and internet modems.

Sometimes, our own devices can be compromised by systems outside of our control, such as internet service providers and other companies who can access our devices remotely. Cisco Prime Home is a system that such companies use to remotely manage things like set-top boxes, modems, and routers, and that system has recently suffered a security vulnerability, Bitdefender’s blog reports.

Basically, the vulnerability is in Cisco Prime Home’s web graphical user interface (GUI) and it could allow a remote, unauthorized attacker to access devices managed by the service with administrator privileges. By sending a series of commands via an unsecured HTTP connection to a specific network address, the attacker can gain the same access to managed devices as an administrator.

Having administrator access to anything is a very big deal and this particular vulnerability is a serious one. Someone who exploits the vulnerability could gain access and control over any device managed by Cisco Prime Home. That means that no matter how carefully you secure your devices yourself, there is another possible avenue of attack that is completely outside of your control and knowledge.

Cisco issued a fix for the service, meaning that the companies who use it to manage your devices should have already updated and resolved the vulnerability. You may not even be aware of which of your service providers are using Cisco Prime Home and so there is really not a lot you can do except hope that those companies are keeping up their end of the security bargain.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
Hackers may attack home networks through Philips Hue smart bulbs vulnerability
philips hue white and color ambiance starter kit deal with lightswitch

Security researchers discovered a vulnerability in the Philips Hue smart bulbs that may allow hackers to infiltrate a home's network.

Cybersecurity firm Check Point revealed the exploit through a blog post, where it detailed the method of attack that hackers may use to take advantage of the bug.

Read more
Eve Cam is a HomeKit indoor security camera that saves your recordings in iCloud
The Eve Cam on a wall.

Apple fans have reason to be excited. There is now an indoor security camera just for you. Eve Systems has released its newest product, the Eve Cam, which is the first indoor camera made exclusively for Apple HomeKit Secure Video, according to the company. When combined with HomeKit Secure Video, any activity detected by the camera is analyzed by your home hub (Apple TV or HomePod) to determine if a threat may be present. You can then view any activity from your iPhone's lock screen.

“Home security footage is highly personal -- that’s why choosing the right indoor camera is so important,” says Jerome Gackel, CEO of Eve Systems. “Eve Cam is the first camera designed exclusively for Apple HomeKit Secure Video, enabling you to keep a close eye on your home while protecting the privacy of your personal space at any time.”

Read more
An Nvidia vulnerability has been found. It’s time to update your drivers
nvidia rtx 2080 super review mem4

Just this month, Nvidia posted a security bulletin on its site alerting consumers that GPUs in its GeForce, Quadro, and Tesla product lines were all affected by serious vulnerabilities. The vulnerabilities range in severity, but get as dangerous as local code execution and privilege escalation, and can be found in all versions of numerous driver tracks that the company provides for its hardware.

Notably, this includes the R430 line that powers the GeForce GPUs. While Nvidia has since issued new patched versions of all of its GeForce and many of its Quadro drivers, patches for some of its Quadro and Tesla drivers have not been released, and in some cases won't be ready for two weeks.

Read more