Skip to main content

Critical Bug Allows CIA To Control 318 Cisco Swtich Models, No Fix Available


Cisco Switch vulnerability
A vulnerability has been spotted in Cisco’s Cluster Management Protocol (CMP) which exposes 318 Cisco Switch models to malicious attacks comprising full control of the device. The flaw arises out of the inability to restrict the use of CMP-specific telnet protocol for local communications. Cisco has suggested some measures for reducing the
attack chances before they push the software update for the device.
The Vault 7 revelation by Wikileaks brought to light the plethora of vulnerabilities in various devices that the CIA can leverage while performing hacking activities. Various companies including Apple and Google confirmed that they’ve fixed the bugs exposed in the CIA data leak. But it appears the dark clouds are still over the roofs of Cisco Systems.
The researchers at Cisco have found a critical vulnerability (CVE-2017-3881) in more than 300 models of their switches. The bug can allow potential hackers and agencies like CIA to take full control of the switches remotely.
According to an advisory, the bug rests on the Cisco Cluster Management Protocol (CMP) and allows an attacker to perform remote code execution with elevated privileges. CMP uses the telnet protocol as a means of signaling and sending commands on internal networks.
Cisco says the vulnerability arises out of the failure to limit the use of telnet options for local communications between clusters. Also, due to the incorrect processing of malformed CMP-specific telnet options.
To take advantage of the vulnerability, an attacker can send “malformed CMP-specific telnet options while establishing a telnet session with an affected Cisco device configured to accept telnet connections.”
“An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device.”
According to the advisory, there is “no workaround for the vulnerability, ” and the company will be pushing software updates in the future. However, it only exists when the affected device is configured to accept incoming telnet connections. So, as a countermeasure, Cisco suggests disabling telnet for incoming connections with the help of the following instructions.
The users who don’t want to disable telnet can reduce the threat intensity by implementing infrastructure access control lists, putting a check on the devices that are authorized to send/receive telnet commands.
If you have something to add, drop your thoughts and feedback.

Comments

Follow Us

WHAT'S HOT

VIDEO: KLY & DJ Maphorisa ft. eMTee & Patoranking – SnapThatSh!t

Ambitiouz Entertainment presents the official music video to “SnapThatSh!t” by its budding act, KLYalongside prolific South African producer, Maphorisa, raving South African rapper, eMTee and Nigeria’s music sensation, Patoranking.

How To Install Ubuntu MATE For The Raspberry Pi 2 and Raspberry Pi 3

Ubuntu MATE:  We have done what we can to optimise the build for the Raspberry Pi 2 and Raspberry Pi 3, you can comfortably use applications such as LibreOffice and Firefox. But the microSDHC I/O throughput is a bottleneck so  we  highly  recommend that you use a Class 6 or Class 10 microSDHC  card.  Ubuntu MATE 16.04 also fully supports the built-in Bluetooth and Wifi on

Windows Subsystem For Linux Is Beta No More, Gets “Full Support” In Windows 10 Fall Creators Update

As we told you earlier, WSL on Windows 10  moved out of beta  in August. It still carries the beta tag in Windows 10 Creators Update. Also, it won’t require people to enable developer

KLY Ft. Wizkid – Scrrr Pull Up (Remix)

Starboy, Wizkid blends with KLY as he adds a verse to Kly’s hottest tune Pull up Scrr!!. The remix comes with heavy greatness verse from the starboy boss as he blended another magic lyrics on the self enriched tune. Song Production credit goes to Wichi 1080.