Affected Systems
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0). Four Crosswork vulnerabilities affect all configurations regardless of device settings.
Exploitation Status
Not known to be actively exploited. Vulnerabilities discovered during internal security review. No public PoC reported.
Business Impact
Five vulnerabilities scored CVSS 10.0, including SQL injection, missing authentication, and file system control flaws in Crosswork; improper access control and authentication bypass in Secure Workload. Cisco devices are high-value targets in enterprise networks. Successful exploitation could enable unauthorized access, credential theft, and lateral movement. Patches available for all affected versions.
Urgency
🟠Within 24 hours
Recommended Actions
- Upgrade Cisco Crosswork Data Gateway, Network Controller, and Planning to version 7.2.1-SP immediately if running 7.2.1 or earlier
- Upgrade Cisco Secure Workload Release 3.10 and earlier to version 3.10.9.1
- Upgrade Cisco Secure Workload Release 4.0 to version 4.0.4.16
- Inventory all Cisco Crosswork and Secure Workload deployments (SaaS and on-premises) to identify affected systems
- Monitor authentication logs and database query logs for anomalous activity, especially failed authentication attempts or SQL errors on Crosswork platforms
