ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco warns about public exploit code for critical flaws in its 220 Series smart switches

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1649
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an auth

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.

NVD description · AI analysis pending
6.7<1%
  • cisco asa 5500 firmware
  • cisco firepower 2100 firmware
  • cisco firepower 4000 firmware
  • +1 more
CVE-2019-1935
+3 in the same advisory: …1937 …1974 …1936
A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unaut

A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The vulnerability is due to the presence of a documented default account with an undocumented default password and incorrect permission settings for that account. Changing the default password for this account is not enforced during the installation of the product. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the scpuser account. This includes full read and write access to the system's database.

NVD description · AI analysis pending
9.8
group max
83% PoC ×2
  • cisco integrated management controller supervisor
  • cisco ucs director
  • cisco ucs director express for big data
CVE-2019-1938
A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote a

A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator privileges on an affected system. The vulnerability is due to improper authentication request handling. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow an unprivileged attacker to access and execute arbitrary actions through certain APIs.

NVD description · AI analysis pending
9.85%
  • cisco ucs director
  • cisco ucs director express for big data
CVE-2019-9506
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influenc

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing.

NVD description · AI analysis pending
8.13%
  • google android
  • google iphone os
  • google mac os x
  • +1 more

Indicators of compromiseAll →

TypeIndicatorContext
ipv41.1.4.4o users should upgrade their switches’ firmware to releases 1.1.4.4 and later as soon as possible. Among the other fixes of par
Full article456 words · extracted from helpnetsecurity.com · click to collapse

Cisco has fixed over 30 vulnerabilities in various solutions, including Cisco UCS Director, Cisco UCS Director Express for Big Data, Cisco IMC Supervisor, and the Cisco 220 Series smart switches.

Cisco 220 Series exploit

Updates by product

Users of Cisco UCS Director and Cisco UCS Director Express for Big Data are advised to upgrade to versions 6.7.3.0 and 3.7.3.0, respectively, as they fix, among other things:

  • CVE-2019-1938, an API authentication bypass vulnerability that could be triggered by a specially crafted HTTP requests sent to an affected device and could allow the attacker to execute arbitrary actions with administrator privileges on an affected system
  • CVE-2019-1935, a documented default account with an undocumented default password and incorrect permission settings that could allow an attacker to log in to an affected system and execute arbitrary commands with the privileges of the scpuser account (this includes full read and write access to the system’s database)
  • CVE-2019-1974, an authentication bypass vulnerability that could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user
  • CVE-2019-1937, another authentication bypass flaw that could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges.

There is no indication that any of these flaws is being exploited in the wild.

Also, all except the first one (CVE-2019-1938) also affect the Cisco Integrated Management Controller Supervisor, which should be upgraded to releases 2.2.1.0 and later, which also fix a considerable number of high-risk flaws in this server management solution.

Cisco already pointed to the relevant security updates for Cisco 220 Series smart switches earlier this month, but they are now saying that public exploit code for all three of the fixed vulnerability exists, so users should upgrade their switches’ firmware to releases 1.1.4.4 and later as soon as possible.

Among the other fixes of particular note in this batch are those for:

  • CVE-2019-9506, a Bluetooth key negotiation vulnerability that can be exploited in a KNOB attack. It affects Cisco’s Webex endpoints and several series of IP phones.
  • CVE-2019-1649, a Secure Boot flaw that could allow an attacker with local access to modify the firmware of many of Cisco’s solutions, including its Adaptive Security Appliances (ASA), Firepower switches, and a huge number of router models.

“The Cisco Product Security Incident Response Team (PSIRT) is aware of the existence of proof-of-concept code that demonstrates [CVE-2019-1649] on the Cisco ASR 1001-X. There are no indications at this time that this proof-of-concept code is publicly available,” the company added.

UPDATE (September 3, 2019, 12:40 a.m. PT):

Security researcher Pedro Ribeiro, who discovered and responsibly disclosed CVE-2019-1935, CVE-2019-1937 and CVE-2019-1936, has published details on these vulnerabilities in his GitHub repository and has released corresponding Metasploit modules.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/08/22/cisco-220-series-exploit/