News: 1673580803

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cisco warns it won't fix critical flaw in small business routers despite known exploit

(2023/01/13)


Cisco "has not and will not release software updates" to address a critical flaw in four small business routers, despite having spotted proof of concept code for an exploit.

The networking giant on Wednesday [1]advised that its model RV016, RV042, RV042G, and RV082 routers are subject to CVE-2023-20025 – a critical-rated authentication bypass vulnerability – as well as the medium-severity rated remote command execution vulnerability CVE-2023-20026.

CVE-2023-20025 could allow an unauthenticated remote attacker to bypass authentication on an affected device, thanks to improper validation of user input within incoming HTTP packets.

[2]

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to bypass authentication and gain root access on the underlying operating system," Cisco's warning states.

[3]

[4]

CVE-2023-20026 is also an HTTP validation problem, but can only be triggered when attackers possess valid administrative credentials for the affected device.

[5]Oops. Cisco installed wrong firmware on some boxes and they report fake ‘severe faults’

[6]Cisco’s Talos security bods predict new wave of Excel Hell

[7]Cisco closes in on debut of cloudy Nexus management service

[8]Cisco unifies GUIs across security range

Cisco won't update the devices, for two reasons.

One is that disabling remote management and blocking access to ports 443 and 60443 is a workaround that prevents exploitation of the flaws.

The other is that the devices have reached end of life. Cisco ended support for the RV082 and RV016 in 2021, and software maintenance ended for the RV042 and RV042G in the same year – but the hardware will be supported until 2025.

[9]

Now for the tricky part: Cisco is "aware that proof-of-concept exploit code is available for the vulnerabilities that are described in this advisory" but "is not aware of any malicious use of the vulnerabilities that are described in this advisory."

But given that criminals routinely hunt for easy-to-attack platforms, it surely won't be long before someone attempts to exploit these vulnerabilities.

Security experts often tell The Register that small businesses are not renowned for their infosec capabilities or diligence. So while the fix is relatively trivial for a technical user, many actual owners of these machines will have no idea how to block access to ports 443 and 60443. That is, if they even receive news of the flaws.

[10]

Throw in the fact that small routers often just work for years at a time without intervention, and it is almost certain some of these devices are ripe for attack – and will be for the foreseeable future. ®

Get our [11]Tech Resources



[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8E5zpoZdBHvCy1utPtmWQAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8E5zpoZdBHvCy1utPtmWQAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8E5zpoZdBHvCy1utPtmWQAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/12/21/cisco_dna_center_wrong_firmware/

[6] https://www.theregister.com/2022/12/21/microsoft_talos_excel_xll_threats/

[7] https://www.theregister.com/2022/12/12/cisco_nexus_cloud/

[8] https://www.theregister.com/2022/12/07/cisco_magnetic_consistent_security_ui/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8E5zpoZdBHvCy1utPtmWQAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8E5zpoZdBHvCy1utPtmWQAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



GraXXoR

I always find this sort of lack of flexibility a little disheartening. Where is the customer concern? Where is the humanity? Surely, offering a post cutoff patch would go a long way to generate goodwill and publicity.

Though playing devil’s advocate, it might raise future expectations and even set them up for legal challenges if the good-will code has some unforeseen side effects. No good deed goes unpunished, etc.

Probably best just to say “fk it! yer on yer own!”

Bubba Von Braun

"Probably best just to say “fk it! yer on yer own!”"

I thought that's exactly what Cisco is saying!! After all "We are CISCO, resistance is futile!"

alain williams

If it was just CISCO that took this attitude I would not be so concerned. These days most corporates take that attitude.

Another part of the problem is that the end-of-support date is hard to find when you buy these things.

Re: Customer concern ?

Pascal Monett

That is soooo last millenium.

These days megacorps don't even need to pretend any more. It's just "fork it over and thank your lucky stars you don't live in China".

It is Cisco, after all.

Yorick Hunt

If you weren't concerned that the NSA, CIA and FBI had backdoor access to your network through Cisco equipment, why would you be concerned if someone else also had a peek in?

You buy based on marketing rather than research, you get what you deserve.

Did I read that right?

Mishak

They drop software updates whist the hardware is still in support? Isn't that the wrong way round?

Re: Did I read that right?

mark l 2

I agree is Mishak, What is the point of hardware support until 2025 if they drop the software support 4 years earlier.

Hello Cisco support our router just died. Don't worry says Cisco another one with outdated OS and unpatched security flaws is on the way to you and will be there shortly.

Cisco :-)

Duncan Macdonald

Having used the US government to disable its main competitor (Huawei), it feels that it no longer needs to provide support to its customers.

There is no sincerer love than the love of food.
-- George Bernard Shaw