ZeroHour
Security Affairspublished ()ingested @securityaffairs

Hardcoded password and Java deserialization flaw found in Cisco products

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0141
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux o

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded credentials. A successful exploit could allow the attacker to access the underlying operating system as a low-privileged user. After low-level privileges are gained, the attacker could elevate to root privileges and take full control of the device. Cisco Bug IDs: CSCvc82982.

NVD description · AI analysis pending
8.4<1%
  • cisco prime collaboration
  • cisco prime collaboration assurance
  • cisco prime collaboration provisioning
CVE-2018-0147
Unauthenticated Java Deserialization RCE in Cisco Secure Access Control System

CVE-2018-0147 is a critical (CVSS 9.8) Java deserialization flaw in Cisco Secure Access Control System (ACS), Cisco's enterprise AAA appliance used for TACACS+/RADIUS network access control. The vulnerability arises from insecure deserialization of user-supplied content: an unauthenticated, remote attacker can trigger it by sending a crafted serialized Java object to the affected software. Successful exploitation allows the attacker to execute arbitrary commands on the device with root privileges, giving full control of the AAA appliance. All Cisco ACS releases prior to release 5.8 patch 9 are affected. The flaw is confirmed exploited in the wild - it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 and recent reporting notes old Cisco vulnerabilities being actively exploited - though no public proof-of-concept is known and ransomware use is undetermined.

Do: Upgrade affected ACS deployments to release 5.8 patch 9 or later per Cisco's instructions (Bug ID CSCvh25988) and treat KEV-listed devices as a patching priority; since ACS is end-of-life, plan migration to Cisco ISE for long-term remediation. In the meantime, restrict network reachability of ACS management interfaces and verify installed ACS version/patch level via the appliance admin console.

9.818% KEV
  • Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9
largeon the order of tens of thousands of ACS appliance deployments (large historical enterprise install base; many organizations have since migrated to Cisco ISE,…
Full article439 words · extracted from securityaffairs.com · click to collapse

The set of security updates recently released by Cisco also includes two advisories for critical vulnerabilities, a hardcoded password, and a Java deserialization flaw.

The lasters set of security updates released by Cisco also includes two advisories for critical vulnerabilities.

The first issue is a hardcoded password, tracked as CVE-2018-0141, that affects Cisco’s Prime Collaboration Provisioning (PCP) and that can be exploited by local attackers to gain full control over a vulnerable equipment.

The Cisco’s Prime Collaboration Provisioning application allows admins to remotely install and maintain Cisco voice and video solutions.

A local attacker just has to connect to the affected system via Secure Shell (SSH) using the hardcoded password, the

“A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software could allow an unauthenticated, local attacker to log in to the underlying Linux operating system.” reads the security advisory published by CISCO.

“The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded credentials. “

The hardcoded password can grant to a local attacker the access to a low-privileged user account, but chaining the vulnerability with other issues there is the risk that the attacker would elevate privileges to root.

The vulnerability has received a Common Vulnerability Scoring System (CVSS) Base score of 5.9, a score normally assigned to medium-severity flaws.

“Although this vulnerability has a Common Vulnerability Scoring System (CVSS) Base score of 5.9, which is normally assigned a Security Impact Rating (SIR) of Medium, there are extenuating circumstances that allow an attacker to elevate privileges to root. For these reasons, the SIR has been set to Critical.” continues Cisco.

Currently, there are no workarounds to address the vulnerability in PCP software, but Cisco has already released patches.

The second critical vulnerability, tracked as CVE-2018-0147, is a Java deserialization flaw that affects Cisco Access Control System (ACS) that can be exploited by an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected device.

“A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device.” reads the security advisory.

“The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object. An exploit could allow the attacker to execute arbitrary commands on the device with root privileges.”

Cisco has released software updates to fix the flaw.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Cisco, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/70003/hacking/cisco-hardcoded-password.html