ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco finds new Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-6366
SNMP Buffer Overflow RCE (EXTRABACON) in Cisco ASA, PIX, and FWSM Firewalls

CVE-2016-6366, known as EXTRABACON (Cisco Bug ID CSCva92151), is a classic buffer overflow (CWE-120) in the SNMP processing of Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3, which runs on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices. A remote, authenticated attacker who knows the device's SNMP credentials (community string or SNMP user) can send crafted IPv4 SNMP packets that trigger the overflow and execute arbitrary code on the firewall, yielding full device control (CVSS 3.1: 8.8, high impact to confidentiality, integrity, and availability). Because these firewalls typically sit at the network perimeter, compromise gives attackers a chokepoint for traffic interception and further lateral movement, so any organization running affected ASA/PIX/FWSM software with SNMP enabled and reachable is at risk. A public exploit was released in 2016 in connection with the Shadow Brokers disclosures of Equation Group tooling, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild. The high EPSS score of 87.6% (100th percentile) combined with the KEV listing indicates elevated near-term exploitation risk, making patching urgent.

Do: Upgrade Cisco ASA Software to a fixed release for Bug ID CSCva92151 per Cisco's security advisory (all versions through 9.4.2.3 are affected), and apply the corresponding vendor fixes for ASA 1000V, PIX, and FWSM as required by the CISA KEV listing. As interim mitigation, restrict SNMP access to trusted management hosts via ACLs, disable SNMP where unused, prefer SNMPv3 with strong credentials over v1/v2c community strings, and review devices for indicators of compromise such as unexplained configuration changes or added user accounts.

8.888% KEV PoC ×3
  • Cisco Adaptive Security Appliance (ASA) Software all versions through 9.4.2.3 (at time of disclosure; runs on ASA 5500, ASA 5500-X, ASA Services Module, ASAv, and Firepower 9300 ASA Security Module)
  • Cisco ASA 1000V Cloud Firewall Software affected per Cisco/CISA; no specific version range provided in source data
  • Cisco PIX Firewall Software affected per Cisco/CISA; no specific version range provided in source data
  • +1 more
mass≈1M+ deployed ASA/PIX/FWSM devices (multi-million-unit ASA installed base; historically tens of thousands of ASA management interfaces exposed on the public…
CVE-2016-6415
IKEv1 Memory Disclosure (BENIGNCERTAIN) in Cisco IOS, IOS XE, and IOS XR

CVE-2016-6415, nicknamed BENIGNCERTAIN, is an information disclosure flaw (CWE-200) in the server-side IKEv1 implementation of Cisco IOS, IOS XE, IOS XR, and Cisco PIX firewalls (Bug IDs CSCvb29204 and CSCvb36055). An unauthenticated remote attacker can trigger it by sending a crafted Security Association (SA) negotiation request to a device's IKEv1 listener, causing the device to leak sensitive information from its memory. The attacker gains access to those leaked memory contents, which may include sensitive secrets such as keys or credentials used by the device. Organizations running affected Cisco IOS 12.2 through 12.4 or 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x or 5.0.x through 5.2.x, or PIX before 7.0 with IKEv1 enabled are affected. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-05-19, confirming in-the-wild exploitation, and EPSS assigns it an 87.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade affected IOS, IOS XE, and IOS XR devices to fixed releases per Cisco's advisory for CVE-2016-6415, as required by the CISA KEV listing; as an interim mitigation, disable IKEv1 where unused or restrict ISAKMP (UDP 500) access to trusted peers. Inventory internet-facing Cisco routers, switches, and firewalls for IKEv1-enabled configurations, since only devices with IKEv1 enabled are exploitable.

7.587% KEV
  • Cisco IOS 12.2 through 12.4 and 15.0 through 15.6
  • Cisco IOS XE through 3.18S
  • Cisco IOS XR 4.3.x and 5.0.x through 5.2.x
  • +1 more
massroughly 840,000+ exposed Cisco systems (2016 internet-wide scan estimates)
Full article422 words · extracted from thehackernews.com · click to collapse

The Hacker NewsSep 20, 2016

Network equipment vendor Cisco is finally warning its customers of another zero-day vulnerability the company discovered in the trove of NSA's hacking exploits and implants leaked by the group calling itself "The Shadow Brokers."

Last month, the Shadow Brokers published firewall exploits, implants, and hacking tools allegedly stolen from the NSA's Equation Group, which was designed to target major vendors including, Cisco, Juniper, and Fortinet.

A hacking exploit, dubbed ExtraBacon, leveraged a zero-day vulnerability (CVE-2016-6366) resided in the Simple Network Management Protocol (SNMP) code of Cisco ASA software that could allow remote attackers to cause a reload of the affected system or execute malicious code.

Now Cisco has found another zero-day exploit, dubbed "Benigncertain," which targets PIX firewalls.

Cisco analyzed the exploit and noted that it had not identified any new flaws related to this exploit in its current products.

But, further analysis of Benigncertain revealed that the exploit also affects Cisco products running IOS, IOS XE and IOS XR software.

Benigncertain leveraged the vulnerability (CVE-2016-6415) that resides in the IKEv1 packet processing code and affects several Cisco devices running IOS operating system and all Cisco PIX firewalls.

IKE (Internet Key Exchange) is a protocol used for firewalls, to provide virtual private networks (VPNs), and even manage industrial control systems.

A remote, unauthorized attacker could use this vulnerability to retrieve memory contents from traffic and disclose critical information such as RSA private keys and configuration information by sending specially crafted IKEv1 packets to affected devices.

"The vulnerability is due to insufficient condition checks in the part of the code that handles IKEv1 security negotiation requests. An attacker could exploit this vulnerability by sending a crafted IKEv1 packet to an affected device configured to accept IKEv1 security negotiation requests," Cisco said in its advisory.

Cisco's IOS operating system XR versions 4.3.x, 5.0.x, 5.1.x and 5.2.x, as well as PIX firewalls versions 6.x and earlier, are vulnerable to this flaw, though the company has not supported PIX since 2009.

Neither Cisco has developed a patch for the flaw, nor any workarounds are available.

The company said the vulnerability is currently under exploit, advising its customers to employ intrusion detection system (IDS) and intrusion prevention systems (IPS) to help stop the attacks.

Cisco promised to release software updates to patch CVE-2016-6415 but did not specify a time frame.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2016/09/cisco-nsa-exploit.html