ZeroHour
Security Affairspublished ()ingested @securityaffairs

Rockwell Automation Allen-Bradley Stratix and ArmorStratix switches are exposed to hack due to Cisco IOS flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0158
+1 in the same advisory: …0156
Unauthenticated DoS via IKEv2 Memory Leak in Cisco IOS and IOS XE Software

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE Software allows an unauthenticated, remote attacker to cause a memory leak or a device reload, resulting in a denial of service. The flaw stems from incorrect processing of certain IKEv2 packets (CWE-401 missing memory release; CWE-20 improper input validation) and is triggered by sending crafted IKEv2 packets to an affected device. A successful attack causes the device to continuously consume memory and eventually reload, disrupting VPN termination and any traffic routed through the device, with high availability impact but no confidentiality or integrity impact (CVSS 3.1: 8.6 High, AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). Affected organizations are those running Cisco IOS or IOS XE on routers, switches, or VPN gateways where IKEv2 processing is enabled and reachable, especially internet-facing edge devices. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 and carries a 7.2% EPSS probability of exploitation within 30 days (94th percentile), though no public proof-of-concept is known.

Do: Apply fixed Cisco IOS/IOS XE releases per the vendor's instructions for Bug ID CSCvf22394, as required by the CISA KEV catalog entry, and verify running releases against the Cisco advisory since affected ranges span many software trains. As interim mitigation, restrict reachability of IKEv2 (UDP 500 and 4500) from untrusted networks on devices that do not need to terminate IKEv2, and monitor memory utilization on internet-facing IOS/IOS XE devices with IKEv2 enabled.

8.6
group max
7% KEV
  • Cisco IOS
  • Cisco IOS XE
masshundreds of thousands of devices (subset of a multi-million-device Cisco IOS/IOS XE installed base; the exploitable subset is IKEv2-enabled, reachable edge/VPN…
CVE-2018-0171
Unauthenticated RCE/DoS in Cisco IOS & IOS XE Smart Install

CVE-2018-0171 is a critical (CVSS 9.8) buffer-overflow vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE, caused by improper validation of packet data (CWE-20, CWE-787). An unauthenticated, remote attacker can trigger it by simply sending a crafted Smart Install message to TCP port 4786 on an affected device, with no credentials or user interaction required. A successful exploit can cause a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution, giving the attacker full control of the switch or router. Any IOS or IOS XE device running the Smart Install service is affected — a configuration commonly present on Catalyst switches — and devices exposed to the internet on TCP 4786 are at direct risk. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog, and both Russian (Static Tundra, FSB-linked) and Chinese (Salt Typhoon) state-sponsored actors have exploited it to compromise unpatched, often end-of-life, Cisco network devices at hundreds of organizations worldwide.

Do: Upgrade IOS/IOS XE to a fixed release per Cisco's advisory (Bug ID CSCvg76186); for end-of-life hardware that cannot be patched, plan replacement given active nation-state targeting of unpatched devices. If Smart Install is not in use, disable it with 'no vstack'; otherwise restrict TCP port 4786 with ACLs to trusted management hosts. Audit internet-facing switches and routers for Smart Install enabled and TCP 4786 exposed, and prioritize those devices for remediation.

9.899% KEV
  • Cisco IOS Devices running affected IOS releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186; Smart I
  • Cisco IOS XE Devices running affected IOS XE releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186)
mass≈250,000+ internet-exposed devices with TCP/4786 open, on top of a multi-million-device IOS/IOS XE installed base
CVE-2018-0172
+1 in the same advisory: …0173
Unauthenticated DoS via DHCP option 82 heap overflow in Cisco IOS and IOS XE

Cisco IOS and IOS XE Software improperly validate DHCP option 82 information received in DHCPv4 packets from DHCP relay agents, creating a heap overflow condition. An unauthenticated, remote attacker can trigger the flaw by sending a crafted DHCPv4 packet with option 82 data to an affected device. Successful exploitation causes the device to reload, resulting in a denial of service; no confidentiality or integrity impact is expected, but availability of the networking device is lost. Any Cisco IOS or IOS XE device that processes option 82 information in DHCPv4 packets is affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added March 3, 2022), indicating confirmed exploitation in the wild, and EPSS assigns it a ~7.8% probability of exploitation over the next 30 days.

Do: Upgrade affected Cisco IOS and IOS XE devices to a fixed release listed in the Cisco security advisory for Bug ID CSCvg62730, per the vendor's instructions. Until patched, restrict DHCPv4 traffic to trusted DHCP relay agents and avoid exposing DHCP relay functionality to untrusted networks, and check whether DHCP relay/option 82 is enabled on exposed devices. Monitor devices for unexpected reloads as a sign of attempted exploitation.

8.68% KEV
  • Cisco IOS Multiple affected releases of Cisco IOS Software; fixed releases are specified per platform in the Cisco security advisory (Bug ID CSCvg62730)
  • Cisco IOS XE Multiple affected releases of Cisco IOS XE Software; fixed releases are specified per platform in the Cisco security advisory (Bug ID CSCvg62730)
massorder of 1 million+ deployed devices, with hundreds of thousands of IOS/IOS XE devices visible in public internet scans (exploitability limited to devices…
CVE-2018-0174
Unauthenticated Remote DoS in Cisco IOS and IOS XE via DHCP Option 82

Cisco IOS Software and Cisco IOS XE Software contain an improper input validation flaw (CWE-20) in the DHCP option 82 encapsulation functionality. An unauthenticated remote attacker can trigger it by sending a crafted DHCPv4 packet carrying option 82 information to a device that processes packets received from DHCP relay agents. A successful exploit causes the affected device to reload, producing a denial of service; the CVSS vector confirms no confidentiality or integrity impact. Any organization running Cisco IOS or IOS XE devices that act as DHCP relay agents or otherwise handle relayed DHCP traffic is potentially affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating observed exploitation, though no public proof-of-concept is known.

Do: Apply updated Cisco IOS/IOS XE releases per Cisco's advisory for Bug ID CSCuh91645, prioritizing devices configured as DHCP relay agents or exposed to untrusted DHCP traffic. As an interim mitigation, disable or restrict option 82 processing/insertion on relay configurations and limit DHCPv4 traffic to trusted relay agents. Verify exposure by auditing IOS/IOS XE devices for DHCP relay configurations and for receipt of relayed DHCP packets.

8.68% KEV
  • Cisco IOS Software Affected releases not enumerated in source data; see Cisco advisory for Bug ID CSCuh91645
  • Cisco IOS XE Software Affected releases not enumerated in source data; see Cisco advisory for Bug ID CSCuh91645
massplausibly hundreds of thousands to millions of IOS/IOS XE devices (estimate)
Full article302 words · extracted from securityaffairs.com · click to collapse

Rockwell Automation is warning that its Allen-Bradley Stratix and ArmorStratix industrial switches are exposed to hack due to security vulnerabilities in Cisco IOS.

According to Rockwell Automation, eight flaws recently discovered recently in Cisco IOS are affecting its products which are used in many sectors, including the critical manufacturing and energy.

The list of flaws includes improper input validation, resource management errors, 7PK errors, improper restriction of operations within the bounds of a memory buffer, use of externally-controlled format string.

“Successful exploitation of these vulnerabilities could result in loss of availability, confidentiality, and/or integrity caused by memory exhaustion, module restart, information corruption, and/or information exposure.” reads the security advisory published by the US ICS-CERT.

Affected models are Stratix 5400, 5410, 5700, 8000 and ArmorStratix 5700 switches running firmware version 15.2(6)E0a and earlier.

The most critical vulnerability is the Cisco CVE-2018-0171 Smart Install, a flaw that affects the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software that could be exploited by an unauthenticated, remote attacker to cause a reload of a vulnerable device or to execute arbitrary code on an affected device.

A couple of weeks ago, the hacking crew “JHT” launched a hacking campaign exploiting Cisco CVE-2018-0171 flaw against network infrastructure in Russia and Iran.

Rockwell has released firmware version 15.2(6)E1 to address the vulnerabilities in its switches.

Rockwell Automation provided mitigations in addition to upgrading the software version:

Cisco has released new Snort Rules at https://www.cisco.com/web/software/286271056/117258/sf-rules-2018-03-29-new.html(link is external) to help address the following vulnerabilities:

  • CVE-2018-0171 – Snort Rule 46096 and 46097
  • CVE-2018-0156 – Snort Rule 41725
  • CVE-2018-0174 – Snort Rule 46120
  • CVE-2018-0172 – Snort Rule 46104
  • CVE-2018-0173 – Snort Rule 46119
  • CVE-2018-0158 – Snort Rule 46110
[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Rockwell Automation, Cisco IOS law)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/71540/hacking/rockwell-automation-flaws.html