News: 1696535112

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Cisco warns of critical flaw in Emergency Responder code

(2023/10/05)


Cisco has issued a security advisory about a vulnerability in its Emergency Responder software that would allow an unauthenticated remote attacker to log in to an affected device using the root account.

The vulnerability, designated CVE-2023-20101, arises from the fact that the root account has default, static credentials that cannot be changed or deleted. Yet again, security through obscurity proves insufficiently obscure.

"This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during development," Cisco explains in its [1]advisory . "An attacker could exploit this vulnerability by using the account to log in to an affected system."

[2]

And in so doing, the attacker could login from wherever and execute arbitrary commands as the root user. Hence the base CVSS score of 9.8.

[3]

[4]

Cisco Emergency Responder is designed to work with Cisco Unified Communications Manager to ensure that emergency calls get routed to a location-appropriate Public Safety Answering Point (PSAP). It supports real-time location tracking, call routing, and automatic notification of security personnel with the location of the caller, among other things.

It's not the sort of system you want taken over by those with malicious intent.

[5]IT networks under attack via critical Confluence zero-day. Patch now

[6]Cat accused of wiping US Veteran Affairs server info after jumping on keyboard

[7]Lorenz ransomware crew bungles blackmail blueprint by leaking two years of contacts

[8]Make-me-root 'Looney Tunables' security hole on Linux needs your attention

The inclusion of hard-coded credentials is a textbook security flaw. Its Common Weakness Enumeration is [9]CWE-798 : Use of Hard-coded Credentials - and the fact that needs a designation speaks volumes. In 2023, according to security organization MITRE, it [10]ranked 18 among the top 25 most stubborn weaknesses.

MITRE places the use of hard-coded credentials into the category "Weaknesses introduced into a system because of a poor security architecture or poor security design choices."

[11]

At least Cisco managed to find the bug "during internal security testing" rather than learning about it from active exploitation. It says there are no workarounds and has released software patches to address the issue.

At least only one particular version of the software is affected: Cisco Emergency Responder Release 12.5(1)SU4. Version 12.5 was released January, 2019.

Prior versions, 11.5(1) and earlier, are not affected. Neither is the latest version, 14. ®

Get our [12]Tech Resources



[1] https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/10/04/critical_confluence_privilege_escalation_bug/

[6] https://www.theregister.com/2023/10/05/hospital_cat_incident/

[7] https://www.theregister.com/2023/10/05/lorenz_ransomware_group_leaks_details/

[8] https://www.theregister.com/2023/10/04/linux_looney_tunables_bug/

[9] https://cwe.mitre.org/data/definitions/798.html

[10] https://cwe.mitre.org/top25/archive/2023/2023_stubborn_weaknesses.html

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZR8yA3F8hhFYpCeBMoYFYQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/



"released January, 2019"

Chris Miller

Good grief! This would have been considered a fundamental flaw in 1989, but in 2019??

Anonymous Coward

What's the problem with hard coded credentials? Someone leaves the business. Still got a way in. Someone forgets the password, Still got a way in. It's a win all round. Sure there may be some naysayers about other people that can get these credentials but isn't it worth the risk for the peace of mind that you will always have a way in? I sometimes leave the keys in my front door on the way out in case I lose them. Never lost my keys that way.

tfewster

You missed the tag or Joke Alert icon.

Ah, the days when you could just do a web search for "default password $DEVICE"...

Anonymous Coward

You can still do that as there are many devices that still don't force you to change it the first time you use it. It's like moving into a new house and not changing the locks. I remember those halcyon days however I was a good person and never used it to harm anyone. I say that but I did change an open Wi-Fi network name in a bar to "big floppy donkey dick". I was a little drunk and thought it quite funny. I was tempted to lock it but decided against it even in my inebriated state.

Did I really need a sarcasm tag good person?

Doctor Syntax

"The inclusion of hard-coded credentials is a textbook security flaw."

Good to see developers following the textbook.

<xtifr> wow, I think I just used libtool to solve a problem -- somebody
help me! :>
<luca> xtifr, STEP AWAY FROM THE KEYBOARD