ZeroHour
The Recordpublished ()ingested

Cisco releases advisories for bug affecting more than 1 million security devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1585
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a use

A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communication from the Launcher to the ASDM.

NVD description · AI analysis pending
8.120% PoC ×2
  • cisco adaptive security device manager
CVE-2022-20828
A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attack

A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER module as the root user. This vulnerability is due to improper handling of undefined command parameters. An attacker could exploit this vulnerability by using a crafted command on the CLI or by submitting a crafted HTTPS request to the web-based management interface of the Cisco ASA that is hosting the ASA FirePOWER module. Note: To exploit this vulnerability, the attacker must have administrative access to the Cisco ASA. A user who has administrative access to a particular Cisco ASA is also expected to have administrative access to the ASA FirePOWER module that is hosted by that Cisco ASA.

NVD description · AI analysis pending
7.249% PoC ×2
  • cisco asa firepower
CVE-2022-20829
A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance

A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to upload an ASDM image that contains malicious code to a device that is running Cisco ASA Software. This vulnerability is due to insufficient validation of the authenticity of an ASDM image during its installation on a device that is running Cisco ASA Software. An attacker could exploit this vulnerability by installing a crafted ASDM image on the device that is running Cisco ASA Software and then waiting for a targeted user to access that device using ASDM. A successful exploit could allow the attacker to execute arbitrary code on the machine of the targeted user with the privileges of that user on that machine. Notes: To successfully exploit this vulnerability, the attacker must have administrative privileges on the device that is running Cisco ASA Software. Potential targets are limited to users who manage the same device that is running Cisco ASA Software using ASDM. Cisco has released and will release software updates that address this vulnerability.

NVD description · AI analysis pending
7.23% PoC ×2
  • cisco isa 3000 firmware
  • cisco asa 5585-x firmware
  • cisco asa 5512-x firmware
  • +1 more
Full article727 words · extracted from therecord.media · click to collapse

Cisco on Thursday released three advisories for vulnerabilities discovered by cybersecurity firm Rapid7 in its Adaptive Security Software (ASA) and ASA-X systems. More than one million Cisco ASA devices are deployed worldwide and are designed to support VPN, IPS, and many other features.

In a report released Thursday, Rapid7 said it discovered 10 different vulnerabilities affecting Cisco ASA, Adaptive Security Device Manager (ASDM), and FirePOWER Services Software for ASA. 

Of the ten, Rapid7 said six of the issues still have not been patched. Cisco told The Record it is publishing three advisories and three software bug release notes related to the issues, which were reported to the company in February and March.

Rapid7’s Lead Security Researcher, Jake Baines, discovered the issues and said the three most critical concerns revolve around CVE-2022-20829, CVE-2021-1585 and CVE-2022-20828. 

CVE-2022-20829 — carrying a CVSS score of 9.1 — relates to Cisco's ASDM, a graphical user interface for remote administration of appliances using ASA. According to Rapid7, a malicious ASDM package can be installed on a Cisco ASA, allowing for arbitrary code to be executed on any system connected to the ASA through ASDM.

“The value of this vulnerability is high because the ASDM package is distributable,” Rapid7 said in a report. “A malicious ASDM package might be installed on an ASA in a supply chain attack, installed by an insider or a third-party vendor/administrator, or simply made available ‘for free’ on the internet for administrators to discover themselves.”

Cisco said in the advisory that CVE-2022-20829 has been patched and that they have no evidence of exploitation, but Rapid7 disagreed in its report, claiming the bug has not been addressed. 

The report also highlights CVE-2021-1585, a bug that Cisco disclosed without a patch in July 2021. The company eventually fixed the issue in a June 2022 update, but Rapid7 says it was able to show that the exploit still works against the latest update. Cisco said it has no evidence that the vulnerability has been exploited. 

Rapid7 noted that the kind of man-in-the-middle attacks that exploit CVE-2021-1585 are “trivial for well-funded APT [advanced persistent threat], and they often have the network position and the motive,” referring to hacking groups linked to nation states. “This vulnerability has been public and unpatched for over a year,” Rapid7 explained. 

Cisco did fix CVE-2022-20828, a vulnerability that allows attackers to achieve root access on ASA-X with FirePOWER Services.

Rapid7 said FirePOWER Services Software — a suite of software that supports the installation of the FirePOWER module on Cisco ASA 5500-X with FirePOWER Services — would be a “fairly ideal location for an attacker to hide or stage attacks.”

Rapid7 has been in discussions with Cisco about the issues through July 2022 and announced plans to present their research at the Black Hat conference on Thursday, despite acknowledging that six of the issues described have not been patched. 

A Cisco spokesperson told The Record that the company is tracking the bugs and appreciates Rapid7 for bringing them to light. 

Rapid7 acknowledged that Cisco does not consider all of the bugs they uncovered “vulnerabilities” but urged organizations that use Cisco ASA to isolate administrative access as much as possible.

Rapid7 said that based on their research, it is unclear whether a patch would be widely adopted if Cisco released one. The company says it scanned the internet for ASDM web portals on June 15, finding that less than 0.5% of internet-facing ASDM had adopted the latest update a week after its release. The most prevalent version they found was one released in 2017.

“Organizations that use Cisco ASA are urged to isolate administrative access as much as possible. That is not limited to simply, ‘Remove ASDM from the internet,’" the company said. "We’ve demonstrated a few ways malicious packages could reasonably end up on an ASA and none of those mechanisms have been patched. Isolating administrative access from potentially untrustworthy users is important.”

Cisco did not respond to requests for clarification about why it considered some of the issues vulnerabilities, and others not.  

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisco-releases-advisories-for-bug-affecting-more-than-1-million-security-devices