ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco Data Center Network Manager flaws fixed, Cisco ASA appliances under attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0296
Unauthenticated DoS and Information Disclosure in Cisco ASA HTTP Web Services

Cisco Adaptive Security Appliance (ASA) contains an improper input validation flaw (CWE-20) in how the device's HTTP web services process URLs. An unauthenticated, remote attacker can trigger it by sending crafted HTTP URLs to the ASA's web server, with no credentials required. Successful exploitation can crash and reload the appliance (denial of service) and can also disclose sensitive device memory contents (information disclosure). Any organization running an ASA, which is commonly deployed as an enterprise edge firewall and VPN gateway with a web management interface (ASDM), is potentially affected wherever that HTTP service is reachable by untrusted users. The flaw has been exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (percentile 100).

Do: Apply updates per vendor instructions, upgrading ASA software to a fixed release identified in Cisco's security advisory. Until patched, restrict access to the appliance's HTTP/ASDM service (http server enable) to trusted management networks only, and disable it on any interface that does not require it. Audit internet-facing ASA devices for exposed web interfaces and review logs for anomalous crafted URL requests.

7.5100% KEV PoC ×2
  • Cisco Adaptive Security Appliance (ASA)
masshundreds of thousands of internet-exposed ASA devices (ASA is among the most common exposed firewalls in public internet scans)
CVE-2019-15975
+3 in the same advisory: …15976 …15977 …15999
Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass

Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

NVD description · AI analysis pending
9.8
group max
96% PoC
  • cisco data center network manager
Full article437 words · extracted from helpnetsecurity.com · click to collapse

Cisco has fixed 12 vulnerabilities in Cisco Data Center Network Manager (DCNM), a platform for managing Cisco switches and fabric extenders that run NX-OS, and has warned about a spike in exploitation attempts of an old flaw affecting Cisco Adaptive Security Appliance (ASA) and Firepower Appliance software.

Cisco Data Center Network Manager flaws

Cisco Data Center Network Manager vulnerabilities

Three critical vulnerabilities (CVE-2019-15975, CVE-2019-15976 and CVE-2019-15977) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device.

“The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit another vulnerability,” Cisco shared.

They are present in APIs and the solution’s web-based management interface, and are caused by static encryption keys and credentials.

The other plugged holes include SQL injection, path traversal, command injection, and read access vulnerabilities, caused by insufficient validation of user-supplied input to some of the solution’s APIs.

There are no workarounds that address any of these, so the company advises administrators to upgrade their Cisco DCNM installations to software releases 11.3(1) and later as soon as possible.

The good news is that they’ve all been discovered and reported by Steven Seeley of Source Incite and are not being actively exploited.

Additionally, Cisco plugged CVE-2019-15999, a security hole in DCNM’s JBoss Enterprise Application Platform (EAP), which exists due to incorrectly configured authentication settings.

Cisco ASA appliances under attack

For those who might have missed it, it’s worth pointing out that Cisco Talos recently warned about a spike in exploitation attempts against CVE-2018-0296, a DoS and information disclosure directory traversal bug in Cisco Adaptive Security Appliance (ASA) and Firepower Appliance software.

“This vulnerability was first noticed being exploited publicly back in June 2018, but it appeared to increase in frequency in the past several days and weeks. As such, we are advising all customers to ensure they are running a non-affected version of code,” threat researcher Nick Biasini noted in late December.

“Additionally, we want to highlight that there is a Snort signature in place to detect this specific attack (46897). Concerned customers should ensure it is enabled in applicable policies that could detect this exploitation attempt.”

Several PoCs for the vulnerability have been published on GitHub since the vulnerability was first disclosed.

Check out Cisco’s advisory to see which devices are affected, and the blog post for instructions on how to check whether your devices are among those.

UPDATE (January 16, 2020, 1:35 a.m. PT):

Steven Seeley, the researcher who discovered and reported most of these Cisco Data Center Network Manager flaws, has published proof-of-concept exploit code for them.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/01/06/cisco-data-center-network-manager-flaws-fixed/