In plain language
What this advisory means
Cisco has identified multiple security weaknesses in its Crosswork product line after an internal review. These issues could allow attackers to control software functionality, access protected credentials, execute harmful database commands, or manipulate files improperly. Cisco released software updates to fix these problems, and no workaround solutions are available. Users are advised to upgrade their software promptly to protect their systems.
Technical explanation
How the issue affects the environment
Cisco Crosswork versions prior to the specified fixed releases contain critical vulnerabilities including CWE-89 (SQL Injection), CWE-306 (Missing Authentication for Critical Function), CWE-73 (External Control of File System), and CWE-522 (Insufficiently Protected Credentials). These weaknesses could lead to remote code execution, unauthorized access, and compromise of confidentiality, integrity, and availability. Each vulnerability grouping was assigned a CVE identifier with max CVSS scores of 10.0 or 9.9, indicating extreme severity. Cisco has released fixed software versions—such as 7.2.1-SP and 2.1.1-SP—that address these vulnerabilities. No workarounds exist; upgrading is required for remediation.
Operational impact
Why teams should care
If exploited, these vulnerabilities could result in full compromise of networks running affected Cisco Crosswork products, allowing attackers to manipulate critical network management functions, steal credentials, corrupt data, or disrupt service availability. This presents significant operational, financial, and reputational risk for organizations relying on these systems. Proactive patching is critical to mitigate this risk.
Immediate action
Cisco strongly recommends customers upgrade affected Crosswork products to the fixed software releases indicated: 7.2.1-SP for Data Gateway, Network Controller, and Planning; 2.1.1-SP for Workflow Manager. These versions fully remediate the known vulnerabilities identified in this advisory. No alternate mitigations or workarounds are available.
Affected and fixed releases
Temporary risk reduction
Cisco has stated that there are no workarounds available to address these vulnerabilities. Full remediation requires upgrading to the provided fixed software releases.
Evidence and validation checklist
- Cisco internal security review found multiple vulnerabilities
- Vulnerabilities grouped by CWE and assigned CVE IDs
- CVSS scores up to 10.0 for critical vulnerabilities
- Affected software versions and fixed releases clearly identified
- No workarounds available
- Official advisory published by Cisco PSIRT
- No known exploitation reported
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
