cisco systems

Cisco Agrees to Pay Over $8 Million For Selling Video Surveillance System with Technical Flaws

Experts believe Cisco’s payout to a whistleblower could set a precedent for future lawsuits against vendors who sell products with security vulnerabilities.

Cisco Systems, one of the largest software and technology equipment sellers in the world, will pay $8.6 million to settle lawsuits claiming the company sold video surveillance technology to government agencies despite knowing the software was flawed.

Fifteen states and the District of Columbia, alongside the Justice Department, sued the company for damages under the False Claims Act, which imposes liability to companies who defraud governmental programs. The agencies that will receive payments from Cisco include Homeland Security, the Secret Service, the Federal Emergency Management Agency and several branches of the military, The New York Times reported.

“We are pleased to have resolved a 2011 dispute involving the architecture of a video security technology product,” Cisco spokeswoman Robyn Blum said in a statement. “There was no allegation or evidence that any unauthorized access to customers’ video occurred as a result of the architecture.”

One of the biggest beneficiaries of the settlement is a single individual: James Glenn, a former subcontractor for Cisco in Denmark. Glenn will receive over $1 million for his role as a whistleblower in the case.

He first warned the company in 2008 that a hacker who successfully gained access to one video camera in a system could eventually gain administrative control of the entire network due to software flaws, Reuters reported. Glenn was laid off five months after the disclosure, but noticed in 2010 that the problem had not been fixed: he could still hack into the system. Shortly afterward, he went to the FBI, which opened an investigation, according to Reuters.

Cisco continued to sell the Video Surveillance Manager software through July 2013, when it disclosed the security flaw and released a patch fixing the issue. In its complaint, the Justice Department said the software was “of no value” and did not meet “its primary purpose: enhancing the security of the agencies that purchase it,” according to the Times.

The flaw was based on faulty access controls, which made the products non-compliant with the federal government’s National Institute of Standards in Technology, which determine the security standards that tech companies must use to do business with the government. The compliance issues set the stage for the lawsuit against Cisco, CNBC reported.

Glenn’s lawyer and other industry experts believe the settlement is the first time a whistleblower has gotten a payout in a false claims cyber case. And those experts think that there could be a flurry of similar whistleblower lawsuits filed under the law, seeking to follow in Glenn’s footsteps.

“[The settlement] clearly “clearly provides an opportunity for entrepreneurial plaintiffs or potential plaintiffs to go around looking for more examples like this,” Gregory Klass, a Georgetown University law professor, told Reuters.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • The Yellow Brick Road

    The road to and throughout Wednesday's and Thursday's ISC West was crowded but it was amazing. Read Now

    • Industry Events
    • ISC West
  • An Inside Look From Napco at ISC West

    Get a look into the excitement at ISC West 2025 from Napco. Hear from some of their top-tech executives live from the show floor. Read Now

    • Industry Events
    • ISC West
  • Upping the Ante

    I am not a betting man in terms of cards, dice, blackjack or that wheel with the black marble racing around the circumference of a spinning wheel, but I would bet on the success of ISC West this year. Read Now

    • Industry Events
    • ISC West
  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.