Dump these insecure phone adapters because we're not fixing them, says Cisco
- Reference: 1683320663
- News link: https://www.theregister.co.uk/2023/05/05/cisco_phone_adapter_vulnerabilitty/
- Source link:
In an [1]advisory , Cisco this week warned about the vulnerability in the SPA112 2-Port Adapter that, if exploited, could allow a remote attacker to essentially take control of a compromised device by seizing full privileges and executing arbitrary code.
The flaw, tracked as [2]CVE-2023-20126 , is rated as "critical," with a base score of 9.8 out of 10.
[3]
Adding to the problem is the fact that the adapter reached its [4]end of life in June 2020, and while the last date to extend or renew a service contract for the product isn't until August 2024, Cisco said in the advisory it will not release firmware updates to address the flaw and there are no workarounds.
[5]
[6]
"Customers are encouraged to migrate to a Cisco ATA 190 Series Analog Telephone Adapter," the manufacturer wrote in its advisory.
The Register has asked Cisco for more information, and will update the story if a response comes in.
[7]
The flaw is in the web-based management interface for the two-port adapter, which is used by organizations to connect analog phones and fax machines (please don't ask us to explain what those are) to voice-over-IP systems without having to upgrade them.
The vulnerability stems from a missing authentication process in the firmware upgrade function, according to Cisco.
"This vulnerability is due to a missing authentication process within the firmware upgrade function," the company wrote. "An attacker could exploit this vulnerability by upgrading an affected device to a crafted version of firmware. A successful exploit could allow the attacker to execute arbitrary code on the affected device with full privileges."
[8]Cisco kindly reveals proof of concept attacks for flaws in rival Netgear's kit
[9]April Patch Tuesday: Ransomware gangs already exploiting this Windows bug
[10]Switchzilla revisits training and cert tools with looming debut of 'Cisco U.'
[11]Burn, backlog, burn: Cisco inferno clears away supply chain hassles
DBAPPsecurity, a network security company in China, alerted Cisco to the vulnerability, according to the network box maker. Cisco's Product Security Incident Response Team (PSIRT) doesn't know of any exploitation of the vulnerability.
The ATA 190 Series adapter has been available for almost a decade and, like the SPA112 adapter, enables enterprises to turn analog devices like phones, fax machines, and paging systems into IP devices. They can then be used by companies with enterprise networks, small offices, and unified communications-as-a-service cloud operations.
[12]
However, the ATA 190 Series may be a relatively short-term solution. It has its own [13]final updates scheduled for March 2024.
Before migrating to the ATA 190 adapters, organizations should make sure the device will address their network needs and that their hardware and software configurations are supported by the device, Cisco wrote.
While there doesn't seem to have been attacks exploiting the vulnerability in the wild, upgrading to still-supported adapters would make sense. Cisco's Talos threat intelligence unit said last month that Russian intelligence operatives, working under the APT28 threat group umbrella, in 2021 [14]exploited an old vulnerability in Cisco routers to gather network data from US and European government agencies.
Cisco had issued a fix for the flaw in 2017, though some routers remain unpatched. Talos said miscreants are only getting better and better at their attacks on networks, including exploiting known flaws in vulnerable devices. ®
Get our [15]Tech Resources
[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW
[2] https://nvd.nist.gov/vuln/detail/CVE-2023-20126
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFV8g3nz7GsdywPu4yfTcgAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.cisco.com/c/en/us/products/collateral/unified-communications/small-business-voice-gateways-ata/eos-eol-notice-c51-743206.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFV8g3nz7GsdywPu4yfTcgAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFV8g3nz7GsdywPu4yfTcgAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFV8g3nz7GsdywPu4yfTcgAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2023/03/22/netgear_router_poc_exploits/
[9] https://www.theregister.com/2023/04/11/april_patch_tuesday_ransomware/
[10] https://www.theregister.com/2023/03/13/cisco_u_certification_training_refresh/
[11] https://www.theregister.com/2023/02/16/cisco_q2_2022/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFV8g3nz7GsdywPu4yfTcgAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.cisco.com/c/en/us/products/collateral/unified-communications/ata-190-series-analog-telephone-adapters/eos-eol-notice-c51-741354.html
[14] https://www.theregister.com/2023/04/18/uk_us_apt28_cisco_routers/
[15] https://whitepapers.theregister.com/
> analog devices like phones, fax machines, and paging systems into IP devices
Irony is that even though they were intended to run over the "analogue" phone network, virtually all fax machines in use since- I'd guess- the 1980s have been based on digital technology at the scanning, transmitting and receiving stages.
Obviously it has to modulate that digital signal for transmission of the analogue phone line, but that applies to pretty much *any* digital technology since they all ultimately rely on the underlying "analogue" real world to represent those digital values.
Also, ever notice that in popular use "digital" is effectively a synonym for "online" these days? That's how we end up with "analogue" DVDs and CDs... you remember them, the audio format whose entire selling point was that it was " [1]Compact Disc Digital Audio "?!! (Rant mode off, etc.)
[1] https://upload.wikimedia.org/wikipedia/commons/thumb/1/14/CDDAlogo.svg/1280px-CDDAlogo.svg.png
If you hear anyone saying "analog CD" you have my permission to slap them with a trout till they stop it.
Typical Lazy Solution
Yay!! More unnecessary e-waste :-(
I hate this kind of approach to tech that sadly seems to be so mainstream these days.