ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco patches leaked 0-day in 300+ of its switches

criticalVulnerabilityimportance 60CVE-2017-3881

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-3881
Unauthenticated RCE in Cisco IOS/IOS XE switches via malformed CMP Telnet options

CVE-2017-3881 is a critical (CVSS 9.8) unauthenticated remote code execution flaw, classified CWE-20, in the Cluster Management Protocol (CMP) processing code of Cisco IOS and IOS XE, which uses Telnet internally for signaling between switch cluster members. Because affected devices accept CMP-specific Telnet options on any inbound Telnet connection and mishandle malformed ones, an unauthenticated attacker who opens a Telnet session to a Telnet-enabled device and sends malformed CMP options can trigger the flaw. Successful exploitation lets the attacker execute arbitrary code with elevated privileges, gaining full control of the device, or force a reload of the switch. Affected hardware spans over 300 switching models per related coverage — Catalyst switches, Embedded Service 2020 and IE Industrial Ethernet switches, several EtherSwitch service modules, the ME 4924-10GE, RF Gateway 10, and the CGESM module for HP — running IOS or IOS XE with Telnet enabled; devices that accept only SSH are not remotely exploitable. The bug was disclosed via the March 2017 WikiLeaks Vault 7 CIA leak (tied to the 'Zero Disco' toolkit in related coverage), patched by Cisco that month, has a public PoC (Exploit-DB 41872), was added to CISA's KEV on 2022-03-25 (ransomware use unknown), and EPSS rates a 99% probability of exploitation in 30 days (100th percentile), so in-the-wild exploitation should be assumed.

Do: Upgrade affected switches to the fixed IOS/IOS XE releases listed in Cisco's advisory for bug CSCvd48893 (the CISA KEV required action is to apply the vendor updates). Until patched, disable Telnet on vty lines and use SSH, or restrict inbound TCP/23 to trusted management hosts, since the bug is only reachable via inbound Telnet sessions. Audit configurations for 'transport input telnet' and prioritize internet-facing or widely reachable Catalyst, IE industrial, and EtherSwitch-service-module devices.

9.899% KEV PoC
  • Cisco IOS (Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 Affected IOS releases on these switching platforms per Cisco's advisory (bug ID CSCvd48893); fixed releases published March 2017
  • Cisco IOS XE (same affected switching platforms) Affected IOS XE releases per Cisco's advisory (bug ID CSCvd48893); fixed releases published March 2017
mass≈1M+ deployed affected switches across 300+ models (only the Telnet-enabled subset is exploitable, likely hundreds of thousands of exposed systems)
Full article328 words · extracted from helpnetsecurity.com · click to collapse

Cisco has plugged a critical security hole in over 300 of its switches, and is urging users to apply the patches as soon as possible because an exploit for it has been available for a month now.

Cisco switch 0day

The vulnerability (CVE-2017-3881)

“A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges,” Cisco explained.

“An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections.”

The vulnerability exists partly because of a failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members, and partly because malformed CMP-specific Telnet options are incorrectly processed. These problems have now apparently been rectified.

Another option for those who, for whatever reason, don’t want to implement the offered patches is to disable the Telnet protocol for incoming connections. Cisco has been recommending the switch to SSH for a while now, and this document contains instructions on how to do it. But this move only eliminates the exploit vector, not the vulnerability.

The list of vulnerable devices is too long to reprint (and you can find it in the advisory), but the overwhelming majority of them are Cisco Catalyst, Embedded Service, and Industrial Ethernet switches.

The exploit

The existence of the vulnerability was publicly revealed in March, as details about it were contained in WikiLeaks’ Vault 7 data dump, believed to have been stolen from the CIA.

In April, security researcher Artem Kondratenko published a limited-efficacy PoC exploit for the vulnerability, but Cisco says they are not “aware of any malicious use of the vulnerability.”

The criticality of the vulnerability is reflected in its CVSS Score: 9.8 (out of 10). So if you own one of these Cisco switches, get patching.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/05/10/cisco-switch-0day-patch/