Friday, April 11, 2014
Facebook's Heartbleed security hole affected Cisco Mobile Experiences
Cisco Connected Mobile Experiences
Connected Mobile Experiences (CMX) is a Wi-Fi platform that can help organizations deliver customized, location-based mobile services to end users. The CMX license on the Cisco MSE includes:- CMX Connect to provide a venue-specific, location-based mobile guest access experience
- CMX Analytics to gain insight into end-user behavior while inside their venue
- CMX for Facebook Wi-Fi to support a transparent guest Wi-Fi sign-on experience and to analyze guest profiles using the Cisco and Facebook Wi-Fi platforms
- CMX Dashboard to build and manage the CMX user journey
Cisco AnyConnect Secure Mobility Client for iOS [CSCuo17488]
Cisco Desktop Collaboration Experience DX650
Cisco Unified 7800 series IP Phones
Cisco Unified 8961 IP Phone
Cisco Unified 9951 IP Phone
Cisco Unified 9971 IP Phone
Cisco TelePresence Video Communication Server (VCS) [CSCuo16472]
Cisco IOS XE [CSCuo19730]
Cisco Unified Communication Manager (UCM) 10.0
Cisco Universal Small Cell 5000 Series running V3.4.2.x software
Cisco Universal Small Cell 7000 Series running V3.4.2.x software
Small Cell factory recovery root filesystem V2.99.4 or later
Cisco MS200X Ethernet Access Switch
Cisco Mobility Service Engine (MSE)
Cisco TelePresence Conductor
Cisco WebEx Meetings Server versions 2.x
___________________________
99% BAD HARDWARE WEEK: That is why Facebook was informed before anyone else ! WHo might be behind ? Let me guess. Open SSL with Heartbleed security hole was applied at Cisco without any control ?? YES, NSA used it !
Currently, the NSA has a trove of thousands of such vulnerabilities that can be used to breach some of the world’s most sensitive computers, according to a person briefed on the matter.
See below Yahoo login and password, easily extracted though being heavily SSL encrypted !