Users of Cisco switches, security appliances need to get patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-0296 | Unauthenticated DoS and Information Disclosure in Cisco ASA HTTP Web Services Cisco Adaptive Security Appliance (ASA) contains an improper input validation flaw (CWE-20) in how the device's HTTP web services process URLs. An unauthenticated, remote attacker can trigger it by sending crafted HTTP URLs to the ASA's web server, with no credentials required. Successful exploitation can crash and reload the appliance (denial of service) and can also disclose sensitive device memory contents (information disclosure). Any organization running an ASA, which is commonly deployed as an enterprise edge firewall and VPN gateway with a web management interface (ASDM), is potentially affected wherever that HTTP service is reachable by untrusted users. The flaw has been exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns a 99.9% probability of exploitation within 30 days (percentile 100). Do: Apply updates per vendor instructions, upgrading ASA software to a fixed release identified in Cisco's security advisory. Until patched, restrict access to the appliance's HTTP/ASDM service (http server enable) to trusted management networks only, and disable it on any interface that does not require it. Audit internet-facing ASA devices for exposed web interfaces and review logs for anomalous crafted URL requests. | 7.5 | 100% | KEV PoC ×2 |
| masshundreds of thousands of internet-exposed ASA devices (ASA is among the most common exposed firewalls in public internet scans) |
Full article296 words · extracted from helpnetsecurity.com · click to collapse
Administrators of Cisco switches, firewalls, and security appliances are advised to take a look at the latest collection of security advisories published by the company, as chances are good they will need to implement some updates.

None of the fixed vulnerabilities are critical or exploited in the wild, but most are high-risk and should be plugged as soon as possible.
The vulnerabilities affect the:
- Cisco NX-OS Software, used by the company’s various series of Nexus switches, line cards and fabric modules
- Cisco FXOS Software, also used by the same switches, Firepower firewalls and appliances, MDS switches and UCS fabric interconnects
Potentially exploitable feature
Cisco also published a separate advisory advising users of Nexus switches to disable the on-by-default PowerOn Auto Provisioning (POAP) feature.
“This feature assists in automating the initial deployment and configuration of Nexus switches. By design, the POAP feature leverages several unauthenticated protocols to obtain the initial configuration file for a device,” the company explained.
“POAP accepts a configuration script from the first DHCP server to respond, and there is no mechanism to establish trust with the DHCP server. An attacker who is able to send a DHCP response could provide a malicious configuration to a device, which could allow the attacker to run commands at the administrator privilege level.”
The company recommends to customers who do not want to use the POAP feature to disable it permanently (how to do that is explained in the advisory).
One year ago Cisco warned about disabling a similar feature that was being leveraged by attackers, so it’s possible they fear the same scenario unfolding.
Finally, those users who have not updated their Cisco ASA and Firepower security appliances since last summer are urged to do so now, as attackers are once again exploiting CVE-2018-0296.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/03/07/cisco-switches-patching/