ISC StormCast for Monday, January 6th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 6 January 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 6th, 2020 edition of the Sands and its Storm Center's Stormcast. |
| 0:07.4 | My name is Johannes Ulrich. |
| 0:08.8 | And today I'm recording from Jacksonville, Florida. |
| 0:13.0 | As always with the new year, there are a number of new laws that went into effect with the new year. |
| 0:19.5 | Now, one law that affects information security is the California Consumer Privacy Act or short |
| 0:27.2 | CCPA. |
| 0:29.3 | It is often compared to the European GDPR and sort of a California version of it. |
| 0:35.9 | And also, just like for GDPR, if your business is not |
| 0:40.1 | located in California, you may still have to comply with it if you are doing business with |
| 0:47.2 | California residents. And now Kevin wrote up a very brief sort of two-minute digest of this new law. So if you want to read up on it, |
| 0:58.9 | it's probably the quickest way to get sort of the high level of what this law is about. |
| 1:07.2 | And Cisco released a total of 12 patches. Now, three vulnerabilities being addressed here are of particular interest in that these are authentication bypass vulnerabilities that allow full administrative access to the Cisco Data Center network manager. |
| 1:27.0 | Interesting that it's three distinct vulnerabilities, but they are actually similar in their nature. |
| 1:35.3 | One for the Rest API, second one for the SOP API. |
| 1:40.3 | Both of them are essentially a static encryption key that's being used to derive |
| 1:46.5 | session tokens. So once someone has one of those appliances, they're able to extract |
| 1:53.6 | the encryption key and use it against other installations of the same software. |
| 2:01.0 | The third one is also very similar. |
| 2:03.9 | Now, this one is sort of the web-based management interface, |
| 2:08.7 | not the APIs as the first two vulnerabilities. |
| 2:13.0 | And in this case, again, it's static credentials. |
| 2:17.0 | So very similar vulnerabilities overall. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

