ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco fixes critical flaw in its Secure Access Control System

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0141
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux o

A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system. The vulnerability is due to a hard-coded account password on the system. An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded credentials. A successful exploit could allow the attacker to access the underlying operating system as a low-privileged user. After low-level privileges are gained, the attacker could elevate to root privileges and take full control of the device. Cisco Bug IDs: CSCvc82982.

NVD description · AI analysis pending
8.4<1%
  • cisco prime collaboration
  • cisco prime collaboration assurance
  • cisco prime collaboration provisioning
CVE-2018-0147
Unauthenticated Java Deserialization RCE in Cisco Secure Access Control System

CVE-2018-0147 is a critical (CVSS 9.8) Java deserialization flaw in Cisco Secure Access Control System (ACS), Cisco's enterprise AAA appliance used for TACACS+/RADIUS network access control. The vulnerability arises from insecure deserialization of user-supplied content: an unauthenticated, remote attacker can trigger it by sending a crafted serialized Java object to the affected software. Successful exploitation allows the attacker to execute arbitrary commands on the device with root privileges, giving full control of the AAA appliance. All Cisco ACS releases prior to release 5.8 patch 9 are affected. The flaw is confirmed exploited in the wild - it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 and recent reporting notes old Cisco vulnerabilities being actively exploited - though no public proof-of-concept is known and ransomware use is undetermined.

Do: Upgrade affected ACS deployments to release 5.8 patch 9 or later per Cisco's instructions (Bug ID CSCvh25988) and treat KEV-listed devices as a patching priority; since ACS is end-of-life, plan migration to Cisco ISE for long-term remediation. In the meantime, restrict network reachability of ACS management interfaces and verify installed ACS version/patch level via the appliance admin console.

9.818% KEV
  • Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9
largeon the order of tens of thousands of ACS appliance deployments (large historical enterprise install base; many organizations have since migrated to Cisco ISE,…
Full article368 words · extracted from helpnetsecurity.com · click to collapse

Cisco has pushed out fixes for security vulnerabilities in a wide variety of its products, including two critical flaws in its Secure Access Control System (ACS) and its Prime Collaboration Provisioning (PCP) software.

cisco acs pcp flaws

About the vulnerabilities

The vulnerability (CVE-2018-0141) in the Cisco Prime Collaboration Provisioning software was found during internal security testing and is due to a hard-coded account password on the system.

“An attacker could exploit this vulnerability by connecting to the affected system via Secure Shell (SSH) using the hard-coded credentials. A successful exploit could allow the attacker to access the underlying operating system as a low-privileged user. After low-level privileges are gained, the attacker could elevate to root privileges and take full control of the device,” the company explained.

While the vulnerability can’t be exploited remotely and only allows low-privilege access, “there are extenuating circumstances that allow an attacker to elevate privileges to root,” they noted. And so the flaw is deemed to be critical.

It affects only version 11.6 of the software, and has been now fixed in releases 12.1 and later.

The vulnerability (CVE-2018-0147) in the Cisco Secure Access Control System can be exploited remotely by an unauthenticated attacker and can be used to achieve remote code execution with root privileges.

“The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object,” the company explained.

It affects all releases of Cisco Secure ACS prior to release 5.8 patch 9. Its exploitation potential is lesser on Cisco Secure ACS systems running release 5.8 Patch 7 or Patch 8, as it the user needs to be authenticated to pull off the compromise.

The vulnerability has been fixed in Cisco Secure ACS 5.8.0.32.9 Cumulative Patch.

Positive Technologies researchers Mikhail Klyuchnikov and Yury Aleynov have been credited with the discovery of the flaw.

Meltdown and Spectre updates

Cisco has been regularly updating the advisory on the CPU side-channel information disclosure vulnerabilities dubbed Meltdown and Spectre since they were first publicly identified in January 2018.

In the latest update, the company has updated the Vulnerable Products table with estimated availability dates for the delivery of fixed software for Cisco UCS Servers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/03/08/cisco-acs-pcp-flaws/