Cisco warns 'unintentional debugging credential' left in some network switches can be abused to hijack equipment
- Reference: 1636071732
- News link: https://www.theregister.co.uk/2021/11/05/cisco_unintentional_debugging_credential_security_alert/
- Source link:
One of these vulnerabilities, CVE-2021-34795, is "an unintentional debugging credential," as Cisco put it, baked into the devices.
What on Earth is an "unintentional debugging credential"? It kinda smells like a backdoor left in by engineers for testing. Cisco's not explained how such a credential was left in a shipping product; we've asked for more details.
[1]
What we do know is that if you know the hidden credential, you can get root-level access to these passive optical network switches, which Cisco [2]suggests are at home in service provider networks.
[3]
[4]
There is an upside to this. As Cisco explains in its [5]advisory , the device needs to have Telnet support enabled, and that's off by default. If Telnet is running (and you can reach the device on the network), you can log in as root using the debugging credential.
The other critical hole is CVE-2021-40113, which can be exploited by an unauthenticated remote attacker to perform a command injection attack on the equipment's web-based management portal, thanks to insufficient validation of user-supplied input.
[6]
"An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface," Cisco explained. "A successful exploit could allow the attacker to execute arbitrary commands on an affected device as the root user."
To pull off such an attack, you must be able to reach the management portal via the device's LAN ports, unless you've enabled Remote Web Management.
But wait, there's more! The 8.6-out-of-10-rated CVE-2021-40112 allows an unauthenticated remote attacker to modify the configuration of the same switches impacted by the other flaws detailed above.
[7]
Cisco has released a software update for the borkable boxen: if you run a Catalyst PON Switch CGP-ONT-1P, CGP-ONT-4P, CGP-ONT-4PV, CGP-ONT-4PVC, or CGP-ONT-4TVCW, you know what to do.
[8]Cisco requires COVID-19 shots for all US staff – even remote workers
[9]Cisco deprecates Microsoft management integrations for UCS servers
[10]Cisco to face trial over trade secrets theft, NDA breach claims after losing attempt to swat Leadfactors lawsuit
Cisco also [11]notified customers of a 9.8-rated flaw in version 21.1.0 and earlier releases of its Policy Suite product.
"A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user," it warned.
Cisco Policy Suite for Mobile is [12]described as offering "cloud-native policy, charging, and subscriber data management functions … providing the control to better monetize your networks and profit from personalized services."
Or, if a third party gets root , someone else can do that monetizing and profiting.
Updating software and installing fresh SSH keys should sort this one out. ®
Updated to add on November 7th at 23:15 UTC
Cisco has sent the following statement to The Register .
"Cisco has security engineering programs and requirements to facilitate use of secure credentials in our products. When improvement areas are identified, we programmatically work to remediate them, provide fixed software, and notify our customers. In this case, the debugging credentials described in the advisory were unintentionally included in affected software versions, and the released software update addresses this issue."
Make of that what you will.
Get our [13]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YYmsLRzEdA19eNx@-hp1AQAAAMU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.cisco.com/c/en/us/products/switches/catalyst-pon-series/index.html#~models
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYmsLRzEdA19eNx@-hp1AQAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYmsLRzEdA19eNx@-hp1AQAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catpon-multivulns-CE3DSYGr
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YYmsLRzEdA19eNx@-hp1AQAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YYmsLRzEdA19eNx@-hp1AQAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2021/11/03/cisco_updates_covid_19_vaccination_policy/
[9] https://www.theregister.com/2021/10/27/ucs_intergration_deprecatoin/
[10] https://www.theregister.com/2021/10/26/cisco_theft_leadfactors/
[11] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cps-static-key-JmS92hNv?
[12] https://www.cisco.com/c/en/us/products/wireless/policy-suite-mobile/index.html
[13] https://whitepapers.theregister.com/
Oh yeah, so this one China order...
They said just cut and paste this here for big order.
Guys, they found this one. Go and hide the others!
It kinda smells like a backdoor left in by engineers for testing .
TFTFY
One of the reasons I prefer open source stuff like OpenWRT and pFSense is the lower probability of crap like this happening. Oh, and much cheaper as well...
To be fair to others, they probably have cool features that I don't know about and/or have no idea how to use, not being adequately versed in the dark arts of VLAN management, etc.
I've been using pFSence at home and at work for years now, pFSense was excellent until NetGate took it over, the last two "updates" have resulted in having to reboot every device connected to it.
Same experience here with pfSense, bad updates & questionable decisions by them. Transitioned all our routers (~30) to OPNSense this year. Additionally, the NetGate ARM hardware is horrible and can't handle a power loss. Trashed that this year as well.
if you're genuinely advocating for OpenWRT for large scale enterprise I just don't know what to tell you.
No, but Cisco push stuff for small companies as well.
If you only have a dozen or two machines in one location then OpeWRT is quite adequate as a router and basic firewall. The ease of saving and restoring configuration allows you to have another cheap system on cold standby if you don't have the budget for fancy HA systems.
Thank goodness it's shoddy Cisco programming
and not Huawei. If it had been Huawei, it would be a National Security incident, whereas here, it's just a deplorable mistake.
Re: Thank goodness it's shoddy Cisco programming
So, when can we expect Huawei to issue a *verty* similar set of patches?
Re: Thank goodness it's shoddy Cisco programming
Well, those backdoors for the 5 eyes need to be installed, so remove the non 5 eyes compliant Huawei kit .
As an aside, I'm puzzled by the terminology
If these are "passive optical network switches", how does the concept of root access apply? That doesn't sound like a passive device to me.
Re: As an aside, I'm puzzled by the terminology
It's Passive Optical Network Switch as in a switch for a Passive Optical Network, not a Passive Switch for an Optical Network.
Basically the fiber and the splitters are unpowered.
Can CVE-2021-40113 turn on telnet?
that would make this a lot more interesting
Yo!!......
......ah!......a "mistake"!!!
*
....and then there's the NSA backdoors which we haven't been told about!!!
*
Yes.....I know.....the NSA isn't in bed with Cisco...........
*
....or in bed with NSO....or Google...............
*
Please........just stop reporting misinformation that some of us simply do not believe!!!!!
No discipline...
I've worked as a sys admin, DBA, and QA. Talking with friends who have had similar careers we came to the conclusion that programmers have the self-discipline of incontinent baboons.
Apologies in advance, but...
Catalyst PWN Series Switches Optical Network
FTFY
So I guess
The NSA was finished using them?
Seriously, how hard is it to track and remove debugging credentials (and accounts, and configurations, etc.)?