ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

BENIGNCERTAIN-like flaw affects various Cisco networking devices

highVulnerability exploited in the wildimportance 60CVE-2016-6415

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-6415
IKEv1 Memory Disclosure (BENIGNCERTAIN) in Cisco IOS, IOS XE, and IOS XR

CVE-2016-6415, nicknamed BENIGNCERTAIN, is an information disclosure flaw (CWE-200) in the server-side IKEv1 implementation of Cisco IOS, IOS XE, IOS XR, and Cisco PIX firewalls (Bug IDs CSCvb29204 and CSCvb36055). An unauthenticated remote attacker can trigger it by sending a crafted Security Association (SA) negotiation request to a device's IKEv1 listener, causing the device to leak sensitive information from its memory. The attacker gains access to those leaked memory contents, which may include sensitive secrets such as keys or credentials used by the device. Organizations running affected Cisco IOS 12.2 through 12.4 or 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x or 5.0.x through 5.2.x, or PIX before 7.0 with IKEv1 enabled are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-05-19, confirming in-the-wild exploitation, and EPSS assigns it an 87.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade affected IOS, IOS XE, and IOS XR devices to fixed releases per Cisco's advisory for CVE-2016-6415, as required by the CISA KEV listing; as an interim mitigation, disable IKEv1 where unused or restrict ISAKMP (UDP 500) access to trusted peers. Inventory internet-facing Cisco routers, switches, and firewalls for IKEv1-enabled configurations, since only devices with IKEv1 enabled are exploitable.

7.587% KEV
  • Cisco IOS 12.2 through 12.4 and 15.0 through 15.6
  • Cisco IOS XE through 3.18S
  • Cisco IOS XR 4.3.x and 5.0.x through 5.2.x
  • +1 more
massroughly 840,000+ exposed Cisco systems (2016 internet-wide scan estimates)
Full article359 words · extracted from helpnetsecurity.com · click to collapse

The leaking of BENIGNCERTAIN, an NSA exploit targeting a vulnerability in legacy Cisco PIX firewalls that allows attackers to eavesdrop on VPN traffic, has spurred Cisco to search for similar flaws in other products – and they found one.

BENIGNCERTAIN

CVE-2016-6415 arises from insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests.

“The IKE protocol is used in the Internet Protocol Security (IPsec) protocol suite to negotiate cryptographic attributes that will be used to encrypt or authenticate the communication session,” the company explained.

The flaw affects Cisco IOS, Cisco IOS XE and Cisco IOS XR Software, and could allow unauthenticated, remote attackers to retrieve memory contents. This could result in the attackers extracting the decryption keys, and using them to decrypt the encrypted traffic that passes through the affected device.

“An attacker could exploit this vulnerability using either IPv4 or IPv6 on any of the listed UDP ports,” they added. “This vulnerability can only be exploited by IKEv1 traffic being processed by a device configured for IKEv1. Transit IKEv1 traffic can not trigger this vulnerability. IKEv2 is not affected. Spoofing of packets that could exploit this vulnerability is limited because the attacker needs to either receive or have access to the initial response from the vulnerable device.”

The vulnerability also exists in some Cisco PIX firewalls, which have not been supported since 2009.

If you’re using a Cisco device that runs one of the aforementioned software, check out the security advisory to see whether the version you’re running is vulnerable, and check back often to see when Cisco will provide a software update to address it.

Cisco pointed out there are no workarounds for addressing the flaw, and noted that its Product Security Incident Response Team is “aware of exploitation of the vulnerability for some Cisco customers who are running the affected platforms.”

Until a security update is provided, administrators of affected devices are advised to keep a close eye on them and to implement intrusion prevention and/or detection systems to spot exploitation attempts.

“Cisco IPS Signatures 7699-0 and Snort SIDs 40220(1), 40221(1), 40222(1) can detect attempts to exploit this vulnerability,” the company concluded.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2016/09/19/beningcertain-cisco-networking-devices/