ZeroHour
Security Affairspublished ()ingested @securityaffairs

Old vulnerabilities in Cisco products actively exploited in the wild

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-12240
Unauthenticated RCE via DHCP Relay in Cisco IOS and IOS XE Software

CVE-2017-12240 is a buffer overflow (CWE-119/CWE-20) in the DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software. An unauthenticated, remote attacker can trigger it by sending a crafted DHCPv4 packet to a device running affected software with the DHCP relay subsystem processing untrusted packets. Successful exploitation allows arbitrary code execution and full control of the system, or alternatively forces a reload that causes a denial of service. Any organization running affected Cisco IOS or IOS XE releases on routers or Layer 3 switches, particularly edge or relay devices reachable over the network, is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating active exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed; EPSS assigns a 13.9% probability of exploitation within 30 days (96th percentile).

Do: Apply the fixed software releases per Cisco's advisory and CISA's required action (apply vendor updates), prioritizing internet-facing routers and devices with DHCP relay configured. As interim mitigation, disable DHCP relay where it is not needed and restrict access to DHCP ports (UDP 67/68) on affected devices using ACLs or upstream firewall rules. Check device inventory for IOS releases in the 12.2–15.6 range and IOS XE releases listed in the advisory, and verify whether DHCP relay is in use on each.

9.814% KEV
  • Cisco IOS 12.2 through 15.6
  • Cisco IOS XE Software affected releases as specified in the Cisco advisory (release numbers not enumerated in source data)
massseveral hundred thousand deployments plausibly affected (Cisco IOS/IOS XE installed base is in the millions; only the subset with DHCP relay enabled and…
CVE-2018-0125
Unauthenticated RCE in Cisco RV132W and RV134W VPN Routers

CVE-2018-0125 is a critical (CVSS 9.8) input-validation flaw in the web interface of Cisco's RV132W ADSL2+ and RV134W VDSL2 small-business VPN routers. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the device's web management interface, which inadequately validates user-controlled input. A successful exploit lets the attacker execute arbitrary code with root privileges and take full control of the router, or alternatively crash the device into a denial-of-condition. Only these two small-business router models are affected; the flaw is fixed in firmware version 1.0.1.11. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) and is being actively exploited in the wild, with a high predicted exploitation probability (EPSS ~55%).

Do: Upgrade affected RV132W and RV134W routers to firmware version 1.0.1.11 or later per Cisco's guidance. Until patched, restrict the web management interface to trusted networks (avoid exposing it to the internet) and check whether your devices are on the CISA KEV list requiring remediation. After patching, review device integrity, as a successful exploit grants full root-level control of the router.

9.855% KEV
  • Cisco RV132W ADSL2+ Wireless-N VPN Router firmware all versions prior to 1.0.1.11
  • Cisco RV134W VDSL2 Wireless-AC VPN Router firmware all versions prior to 1.0.1.11
moderateroughly several thousand internet-exposed devices (installed base likely higher; SOHO/small-office deployments)
CVE-2018-0147
Unauthenticated Java Deserialization RCE in Cisco Secure Access Control System

CVE-2018-0147 is a critical (CVSS 9.8) Java deserialization flaw in Cisco Secure Access Control System (ACS), Cisco's enterprise AAA appliance used for TACACS+/RADIUS network access control. The vulnerability arises from insecure deserialization of user-supplied content: an unauthenticated, remote attacker can trigger it by sending a crafted serialized Java object to the affected software. Successful exploitation allows the attacker to execute arbitrary commands on the device with root privileges, giving full control of the AAA appliance. All Cisco ACS releases prior to release 5.8 patch 9 are affected. The flaw is confirmed exploited in the wild - it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 and recent reporting notes old Cisco vulnerabilities being actively exploited - though no public proof-of-concept is known and ransomware use is undetermined.

Do: Upgrade affected ACS deployments to release 5.8 patch 9 or later per Cisco's instructions (Bug ID CSCvh25988) and treat KEV-listed devices as a patching priority; since ACS is end-of-life, plan migration to Cisco ISE for long-term remediation. In the meantime, restrict network reachability of ACS management interfaces and verify installed ACS version/patch level via the appliance admin console.

9.818% KEV
  • Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9
largeon the order of tens of thousands of ACS appliance deployments (large historical enterprise install base; many organizations have since migrated to Cisco ISE,…
CVE-2018-0171
Unauthenticated RCE/DoS in Cisco IOS & IOS XE Smart Install

CVE-2018-0171 is a critical (CVSS 9.8) buffer-overflow vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE, caused by improper validation of packet data (CWE-20, CWE-787). An unauthenticated, remote attacker can trigger it by simply sending a crafted Smart Install message to TCP port 4786 on an affected device, with no credentials or user interaction required. A successful exploit can cause a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution, giving the attacker full control of the switch or router. Any IOS or IOS XE device running the Smart Install service is affected — a configuration commonly present on Catalyst switches — and devices exposed to the internet on TCP 4786 are at direct risk. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog, and both Russian (Static Tundra, FSB-linked) and Chinese (Salt Typhoon) state-sponsored actors have exploited it to compromise unpatched, often end-of-life, Cisco network devices at hundreds of organizations worldwide.

Do: Upgrade IOS/IOS XE to a fixed release per Cisco's advisory (Bug ID CSCvg76186); for end-of-life hardware that cannot be patched, plan replacement given active nation-state targeting of unpatched devices. If Smart Install is not in use, disable it with 'no vstack'; otherwise restrict TCP port 4786 with ACLs to trusted management hosts. Audit internet-facing switches and routers for Smart Install enabled and TCP 4786 exposed, and prioritize those devices for remediation.

9.899% KEV
  • Cisco IOS Devices running affected IOS releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186; Smart I
  • Cisco IOS XE Devices running affected IOS XE releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186)
mass≈250,000+ internet-exposed devices with TCP/4786 open, on top of a multi-million-device IOS/IOS XE installed base
CVE-2021-1497
Root Command Injection in Cisco HyperFlex HX Installer Virtual Machine

CVE-2021-1497 is a command injection flaw (CWE-78) in the Cisco HyperFlex HX Installer Virtual Machine, caused by insufficient validation of input processed by the installer VM. An attacker who can reach the affected installer VM can submit crafted input that causes arbitrary operating system commands to run with root privileges, giving full control of the appliance. Only organizations that have deployed the Cisco HyperFlex HX Installer Virtual Machine, typically as part of standing up or managing a HyperFlex hyperconverged cluster, are affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating it is being exploited in the wild, and its EPSS score of 99.9% (100th percentile) implies a very high likelihood of exploitation attempts within 30 days. No public proof-of-concept is known, and CVSS scoring is not yet available.

Do: Apply updates to the HyperFlex HX Installer Virtual Machine per Cisco's vendor instructions, as required by the CISA KEV catalog. Check whether the installer VM is still deployed (including on internal management networks), restrict network access to it from untrusted sources, and decommission it if it is no longer needed.

9.8100% KEV PoC
  • Cisco HyperFlex HX Installer Virtual Machine
nichelikely thousands of deployments at most, with only a subset internet-exposed (unknown exact count)
Full article337 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 19, 2022

IT giant Cisco is warning of threat actors exploiting many old vulnerabilities in attacks in the wild.

Cisco has updated multiple security advisories to warn of the active exploitation of several old vulnerabilities impacting its products.

The bugs, some of which are rated as ‘critical’ severity, impact Cisco IOS, NX-OS, and HyperFlex software.

Below are the critical vulnerabilities being exploited in attacks in the wild:

  • CVE-2017-12240 (CVSS score of 9.8) – The vulnerability affects the DHCP relay subsystem in IOS and IOS XE software. The vulnerability could be exploited by a remote and unauthenticated attacker that can execute arbitrary code and gain full control of the targeted system. The flaw could be also exploited to cause a denial-of-service (DoS) condition by triggering a buffer overflow via specially crafted DHCPv4 packets.
  • CVE-2018-0125 (CVSS score of 9.8) – A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. 
  • CVE-2018-0147 (CVSS score of 9.8) – The vulnerability is a Java deserialization issue that affects Cisco Access Control System (ACS) that can be exploited by an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected device.
  • CVE-2018-0171 (CVSS score of 9.8) – The vulnerability affects the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software, it could be exploited by an unauthenticated, remote attacker to cause a reload of a vulnerable device or to execute arbitrary code on an affected device.
  • CVE-2021-1497 (CVSS score of 9.8) –  The vulnerability is a Command Injection issue that resides in the web-based management interface of Cisco HyperFlex HX.

Organizations are recommended to review the Cisco’s advisories and apply security patches released by the company.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Moshen Dragon)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/139821/security/cisco-old-vulnerabilities-exploitation.html