ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco Warns of Vulnerability in IOS and IOS XE Software After Exploitation Attempts

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20034
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticse

Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could allow an unauthenticated, remote attacker to access the Elasticsearch configuration database of an affected device with the privileges of the elasticsearch user. These vulnerability is due to the presence of a static username and password configured on the vManage. An attacker could exploit this vulnerability by sending a crafted HTTP request to a reachable vManage on port 9200. A successful exploit could allow the attacker to view the Elasticsearch database content. There are workarounds that address this vulnerability.

NVD description · AI analysis pending
7.5<1%
  • cisco sd-wan
CVE-2023-20109
Out-of-Bounds Write in Cisco IOS/IOS XE GET VPN Enables Authenticated RCE

CVE-2023-20109 is an out-of-bounds write (CWE-787) in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and Cisco IOS XE, caused by insufficient validation of Group Domain of Interpretation (GDOI) and G-IKEv2 protocol attributes. An authenticated, remote attacker with administrative control of either a GET VPN group member or key server can trigger the flaw by compromising the installed key server or by modifying a group member's configuration to point at an attacker-controlled key server, then sending crafted GDOI/G-IKEv2 attributes. A successful exploit allows the attacker to execute arbitrary code and gain full control of the device, or to crash/reload it, causing a denial-of-service condition. Only organizations running Cisco IOS/IOS XE devices with the GET VPN feature configured (as group members or key servers) are affected; CVSS 3.1 rates it 6.6 (medium) because exploitation requires high privileges and high attack complexity. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-10, indicating confirmed in-the-wild exploitation, while EPSS estimates a 2.3% probability of exploitation in the next 30 days and no public PoC is known.

Do: Upgrade affected devices to a fixed release identified in Cisco's security advisory, and inventory GET VPN deployments with 'show crypto gdoi' to identify group members and their key servers. Because exploitation requires a compromised or attacker-controlled key server, harden and restrict access to key servers, verify that group member configurations point only to legitimate key servers, and rotate GET VPN keys if compromise is suspected. Per the CISA KEV required action, apply vendor mitigations promptly or discontinue use where mitigations are unavailable.

6.62% KEV
  • Cisco IOS
  • Cisco IOS XE
largeon the order of tens of thousands of devices (GET VPN group members/key servers within Cisco's multi-million-unit IOS/IOS XE installed base; not typically…
CVE-2023-20252
+2 in the same advisory: …20262 …20253
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker

A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper authentication checks for SAML APIs. An attacker could exploit this vulnerability by sending requests directly to the SAML API. A successful exploit could allow the attacker to generate an authorization token sufficient to gain access to the application.

NVD description · AI analysis pending
9.8
group max
1%
  • cisco catalyst sd-wan manager
CVE-2023-20254
A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to acce

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vulnerability requires the multi-tenant feature to be enabled. This vulnerability is due to insufficient user session management within the Cisco Catalyst SD-WAN Manager system. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to gain unauthorized access to information about another tenant, make configuration changes, or possibly take a tenant offline causing a denial of service condition.

NVD description · AI analysis pending
8.8<1%
  • cisco sd-wan manager
Full article363 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 29, 2023Vulnerability / Network Security

Cisco is warning of attempted exploitation of a security flaw in its IOS Software and IOS XE Software that could permit an authenticated remote attacker to achieve remote code execution on affected systems.

The medium-severity vulnerability is tracked as CVE-2023-20109, and has a CVSS score of 6.6. It impacts all versions of the software that have the GDOI or G-IKEv2 protocol enabled.

The company said the shortcoming "could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash."

It further noted that the issue is the result of insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature and it could be weaponized by either compromising an installed key server or modifying the configuration of a group member to point to a key server that is controlled by the attacker.

The vulnerability is said to have been discovered following an internal investigation and source code audit initiated after an "attempted exploitation of the GET VPN feature."

The revelation comes as Cisco detailed a set of five flaws in Catalyst SD-WAN Manager (versions 20.3 to 20.12) that could allow an attacker to access an affected instance or cause a denial of service (DoS) condition on an affected system -

  • CVE-2023-20252 (CVSS score: 9.8) - Unauthorized Access Vulnerability
  • CVE-2023-20253 (CVSS score: 8.4) - Unauthorized Configuration Rollback Vulnerability
  • CVE-2023-20034 (CVSS score: 7.5) - Information Disclosure Vulnerability
  • CVE-2023-20254 (CVSS score: 7.2) - Authorization Bypass Vulnerability
  • CVE-2023-20262 (CVSS score: 5.3) - Denial-of-Service Vulnerability

Successful exploitation of the bugs could allow the threat actor to gain unauthorized access to the application as an arbitrary user, bypass authorization and roll back controller configurations, access the Elasticsearch database of an affected system, access another tenant managed by the same instance, and cause a crash.

Customers are recommended to upgrade to a fixed software release to remediate the vulnerabilities.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/09/cisco-warns-of-vulnerability-in-ios-and.html