It's 2021 and you can hijack a Cisco SD-WAN deployment with malicious IP traffic and a buffer overflow. Patch now
- Reference: 1611299044
- News link: https://www.theregister.co.uk/2021/01/22/cisco_critical_vulnerabilities/
- Source link:
The worst of the bugs can be exploited by sending specially crafted IP packets to a vulnerable installation, and overflowing a memory buffer to ultimately execute code as root on the machine, allowing the box to be completely commandeered. Another set of flaws can be abused by sending HTTP requests that trigger arbitrary command execution to again hijack the machine. You should install updates to address these vulnerabilities as soon as possible.
[1]
Here's a quick list:
Cisco SD-WAN Buffer Overflow Vulnerabilities ( [2]CVE-2021-1300, CVE-2021-1301 ): Systems running the Cisco SD-WAN software – such as SD-WAN vEdge Routers – can be exploited "by sending crafted IP traffic through an affected device, which may cause a buffer overflow when the traffic is processed." A successful attack can result in the execution of arbitrary code on the underlying operating system with root privileges, which means you basically hand over the gear to a stranger. No authentication is needed; you just have to be able to send traffic to the software.
[3]
That's the 1300 bug. The 1301 can be exploited by an authenticated user to knock out a vulnerable machine. According to Cisco, "due to insufficient input validation of user-supplied input that is read by the system during the establishment of an SSH connection," a hacker could submit a maliciously crafted file, overflow a buffer, and denial-of-service the box. Both holes were found by Switchzilla's James Spadaro during internal security testing.
Cisco SD-WAN Command Injection Vulnerabilities ( [4]CVE-2021-1260, CVE-2021-1261, CVE-2021-1262, CVE-2021-1263, CVE-2021-1298, CVE-2021-1299 ): These can be exploited by authenticated users to gain root-level privileges on a system running the vulnerable software. This can be achieved via the command-line interface, the tcpdump command, a device template file, and a single-sign-on configuration file. These programming blunders were discovered through a mix of diagnosing customer support tickets and internal security testing at Cisco.
Cisco DNA Center Command Runner Command Injection Vulnerability ( [5]CVE-2021-1264 ): An authenticated remote user can supply a maliciously "crafted input during command execution or via a crafted command runner API call. A successful exploit could allow the attacker to execute arbitrary CLI commands on devices managed by Cisco DNA Center." It was found during an internal security audit.
Cisco Smart Software Manager Satellite Web UI Command Injection Vulnerabilities ( [6]CVE-2021-1138, CVE-2021-1139, CVE-2021-1140, CVE-2021-1141, CVE-2021-1142 ): These bugs can be exploited to run arbitrary commands on a vulnerable installation by sending specially crafted HTTP requests to the web interface. Bugs 1139 and 1141 require authentication and will run the commands as root, and the others require none at all and will run the commands as a high-privilege account. They were found during an internal security audit.
[7]
Cisco believes none of the above are being exploited in the wild. Switchzilla also patched a [8]bunch of other vulnerabilities, such as a Cisco Secure Web Appliance privilege escalation flaw ( [9]CVE-2020-3367 ); Cisco SD-WAN vManage authorization bypass vulnerabilities ( [10]CVE-2021-1302, CVE-2021-1304, CVE-2021-1305 ); and Cisco Data Center Network Manager SQL Injection Vulnerabilities ( [11]CVE-2021-1247, CVE-2021-1248 ). ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YAqwS161qRYmxSLRa1XffwAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-bufovulns-B5NrSHbj
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YAqwS161qRYmxSLRa1XffwAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
[5] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dnac-cmdinj-erumsWh9
[6] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-multici-pgG5WM5A
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YAqwS161qRYmxSLRa1XffwAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://tools.cisco.com/security/center/publicationListing.x
[9] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-prv-esc-nPzWZrQj
[10] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-abyp-TnGFHrS
[11] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-sql-inj-OAQOObP
[12] https://whitepapers.theregister.com/
1980s
That fits.
Have just bought a 2500 desk top switch. (I know, I know. Don’t go on.)
The web interface is so crap that you can’t even fix a static address on the management vlan.
Apparently they have known about this for years.
The work around is to use the cli except, their example doesn’t actually work.
So, this morning, I am having to go back ten years in my head, armed with the eighty odd page manual, and do the fix myself.
Utter crap!
"does nobody at Cisco understand sanitizing inputs?"
Does anyone, anywhere, understand sanitising inputs? Quite probably yes.
So why is this the most common entry point for network appliance and web compromises for over 30 years?
The majority of testing I've observed professionally is restricted to checking that expected inputs work. Checking for the unexpected is understandably harder as the field is typically much larger, but it's not impossible. Just takes resources and time, which are generally frowned on by the bean counters. There must be many developers that have to grit their teeth at products they feel to be unfinished being pushed out the door.
Well, obviously.
It's software.
General rule is that if you don't want it to be possible, you have to isolate it using hardware. If you don't want arbitrary memory access for a process, for instance, there's no point in relying on the OS to do that for you. You have to have a hardware mechanism to enforce that.
Software-defined-anything is just software, vulnerable to all the same problems that all software has.
A buffer overflow parsing packets?
The early 1980s is on line one, they're demanding their vulnerability back.
What's next? Default root passwords, shipped pre-installed for your convenience?
Seriously, does nobody at Cisco understand sanitizing inputs? And worse, is there no such thing as testing code before shipping anymore? That's sad.