ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Cisco fixes a host of security holes, including latest Apache Struts flaw

criticalExploit / PoC exploited in the wildimportance 60CVE-2018-0423CVE-2018-11776CVE-2018-0435

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0423
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco R

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to cause a denial of service condition or to execute arbitrary code. The vulnerability is due to improper boundary restrictions on user-supplied input in the Guest user feature of the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device, triggering a buffer overflow condition. A successful exploit could allow the attacker to cause the device to stop responding, resulting in a denial of service condition, or could allow the attacker to execute arbitrary code.

NVD description · AI analysis pending
8.17%
  • cisco rv110w firmware
  • cisco rv130w firmware
  • cisco rv215w firmware
CVE-2018-0435
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organization

A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication configurations for the API interface of Cisco Umbrella. An attacker could exploit this vulnerability to view and potentially modify data for their organization or other organizations. A successful exploit could allow the attacker to read or modify data across multiple organizations.

NVD description · AI analysis pending
9.11%
  • cisco umbrella
CVE-2018-11776
Apache Struts Remote Code Execution via Missing or Wildcard Namespace

Apache Struts 2 contains an improper input validation flaw (CWE-20) that allows unauthenticated remote code execution when an attacker-controlled namespace (for example, part of the request URL path) is evaluated as an OGNL expression on the server. It is triggered under two circumstances: (1) the alwaysSelectFullNamespace option is true and a result defined in the configuration has no namespace while its parent package's namespace is unset or a wildcard, or (2) a URL tag in a template has no namespace under the same parent-package conditions. An attacker who can reach an application in one of these configurations gains arbitrary code execution with the privileges of the application server, so any organization running affected Struts 2 releases (2.3.7-2.3.34 and 2.5-2.5.16) in such configurations is exposed. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild (ransomware use unknown), and EPSS currently assigns a 100% probability of exploitation within 30 days. CVSS is not yet scored in this feed, but the KEV listing and EPSS signal indicate urgent patching priority.

Do: Upgrade Apache Struts to 2.3.35 or 2.5.17 (or later) on all applications, prioritizing internet-facing ones, per vendor instructions. If upgrading is not immediately possible, set alwaysSelectFullNamespace to false and ensure every result and URL tag specifies an explicit, non-wildcard namespace. Audit configurations, especially applications using the Convention Plugin or wildcard namespaces, for the vulnerable conditions and review web server logs for signs of OGNL injection in namespace values.

8.1100% KEV PoC ×5
  • Apache Struts 2 2.3.7-2.3.34 and 2.5-2.5.16 (fixed in 2.3.35 and 2.5.17, per vendor advisory)
massmillions of end users behind on the order of tens of thousands of internet-exposed Apache Struts deployments
Full article256 words · extracted from helpnetsecurity.com · click to collapse

Cisco has plugged a heap of security holes – three of which are critical – in a variety of its products.

Cisco Apache Struts

The critical flaws

The flaws deemed critical are:

  • A DoS and RCE vulnerability (CVE-2018-0423) in the web-based management interface of three series of Cisco wireless VPN routers: RV110W, RV130W, and RV215W. Unfortunately, it has only been fixed in the RV130W series.
  • An Apache Struts RCE vulnerability (CVE-2018-11776) that affects twenty different Cisco products. This is the vulnerability for which a PoC was recently found online and is being actively exploited in the wild. For the time being, only one patch for one product (Cisco Identity Services Engine) has been released, and the company has published a schedule for some of the other releases.
  • A vulnerability in the Cisco Umbrella API (CVE-2018-0435) could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. Cisco has addressed the issue and no user action is required.

The rest

Cisco has also patched a range of vulnerabilities affecting the Webex Meetings Client, the Cisco Webex Teams, two high-impact flaws in the Cisco Umbrella Enterprise Roaming Client (reported and detailed by Critical Start’s Section 8 cybersecurity team), other high-impact vulnerabilities in the three router series mentioned above, the SD-WAN solution certifications platform, and more.

These range from privilege escalation and certificate validation to DoS, command injection, and XSS flaws.

Administrators are advised to review the advisories concerning the products they use and to implement the provided updates and/or mitigations.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/09/06/cisco-apache-struts/