Cisco warns of critical flaw in Emergency Responder code
- Reference: 1696535112
- News link: https://www.theregister.co.uk/2023/10/05/cisco_icritical_emergency/
- Source link:
The vulnerability, designated CVE-2023-20101, arises from the fact that the root account has default, static credentials that cannot be changed or deleted. Yet again, security through obscurity proves insufficiently obscure.
"This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during development," Cisco explains in its [1]advisory . "An attacker could exploit this vulnerability by using the account to log in to an affected system."
[2]
And in so doing, the attacker could login from wherever and execute arbitrary commands as the root user. Hence the base CVSS score of 9.8.
[3]
[4]
Cisco Emergency Responder is designed to work with Cisco Unified Communications Manager to ensure that emergency calls get routed to a location-appropriate Public Safety Answering Point (PSAP). It supports real-time location tracking, call routing, and automatic notification of security personnel with the location of the caller, among other things.
It's not the sort of system you want taken over by those with malicious intent.
[5]IT networks under attack via critical Confluence zero-day. Patch now
[6]Cat accused of wiping US Veteran Affairs server info after jumping on keyboard
[7]Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts
[8]Make-me-root 'Looney Tunables' security hole on Linux needs your attention
The inclusion of hard-coded credentials is a textbook security flaw. Its Common Weakness Enumeration is [9]CWE-798 : Use of Hard-coded Credentials - and the fact that needs a designation speaks volumes. In 2023, according to security organization MITRE, it [10]ranked 18 among the top 25 most stubborn weaknesses.
MITRE places the use of hard-coded credentials into the category "Weaknesses introduced into a system because of a poor security architecture or poor security design choices."
[11]
At least Cisco managed to find the bug "during internal security testing" rather than learning about it from active exploitation. It says there are no workarounds and has released software patches to address the issue.
At least only one particular version of the software is affected: Cisco Emergency Responder Release 12.5(1)SU4. Version 12.5 was released January, 2019.
Prior versions, 11.5(1) and earlier, are not affected. Neither is the latest version, 14. ®
Get our [12]Tech Resources
[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/10/04/critical_confluence_privilege_escalation_bug/
[6] https://www.theregister.com/2023/10/05/hospital_cat_incident/
[7] https://www.theregister.com/2023/10/05/lorenz_ransomware_group_leaks_details/
[8] https://www.theregister.com/2023/10/04/linux_looney_tunables_bug/
[9] https://cwe.mitre.org/data/definitions/798.html
[10] https://cwe.mitre.org/top25/archive/2023/2023_stubborn_weaknesses.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
What's the problem with hard coded credentials? Someone leaves the business. Still got a way in. Someone forgets the password, Still got a way in. It's a win all round. Sure there may be some naysayers about other people that can get these credentials but isn't it worth the risk for the peace of mind that you will always have a way in? I sometimes leave the keys in my front door on the way out in case I lose them. Never lost my keys that way.
You missed the
Ah, the days when you could just do a web search for "default password $DEVICE"...
You can still do that as there are many devices that still don't force you to change it the first time you use it. It's like moving into a new house and not changing the locks. I remember those halcyon days however I was a good person and never used it to harm anyone. I say that but I did change an open Wi-Fi network name in a bar to "big floppy donkey dick". I was a little drunk and thought it quite funny. I was tempted to lock it but decided against it even in my inebriated state.
Did I really need a sarcasm tag good person?
"The inclusion of hard-coded credentials is a textbook security flaw."
Good to see developers following the textbook.
"released January, 2019"
Good grief! This would have been considered a fundamental flaw in 1989, but in 2019??