5 High Impact Flaws Affect Cisco Routers, Switches, IP Phones and Cameras
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3110 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent A vulnerability in the Cisco Discovery Protocol implementation for the Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP Camera. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to the targeted IP Camera. A successful exploit could allow the attacker to expose the affected IP Camera for remote code execution or cause it to reload unexpectedly, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). This vulnerability is fixed in Video Surveillance 8000 Series IP Camera Firmware Release 1.0.7 and later. NVD description · AI analysis pending | 8.8 | 6% |
| — | ||
| CVE-2020-3111 | A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code A vulnerability in the Cisco Discovery Protocol implementation for the Cisco IP Phone could allow an unauthenticated, adjacent attacker to remotely execute code with root privileges or cause a reload of an affected IP phone. The vulnerability is due to missing checks when processing Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to the targeted IP phone. A successful exploit could allow the attacker to remotely execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2020-3118 | Format String Vulnerability in Cisco IOS XR Discovery Protocol Allows Adjacent RCE CVE-2020-3118 is a format string vulnerability (CWE-134) in the Cisco Discovery Protocol (CDP) implementation of Cisco IOS XR Software, caused by improper validation of string input from certain fields in CDP messages. An unauthenticated attacker who is Layer 2 adjacent (on the same broadcast domain) can trigger it by sending a malicious CDP packet to an affected device, causing a stack overflow (CWE-787). A successful exploit allows the attacker to execute arbitrary code with administrative privileges on the device, or alternatively to cause a device reload (denial of service). Any organization running Cisco IOS XR — typically service-provider and large-enterprise core, edge, and aggregation routers — is affected whenever CDP is enabled on interfaces reachable by an attacker at Layer 2. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, with no public PoC identified and an EPSS estimate of 11.7% (96th percentile) for exploitation within 30 days. Do: Apply updates to affected Cisco IOS XR devices per Cisco's advisory, as required by the CISA KEV catalog. As interim mitigation, disable Cisco Discovery Protocol on interfaces connected to untrusted Layer 2 segments or restrict broadcast-domain access to trusted devices. Prioritize IOS XR devices where untrusted users, partners, or shared infrastructure exist on the same VLAN or broadcast domain, since exploitation requires only L2 adjacency. | 8.8 | 12% | KEV |
| mass≈100,000+ IOS XR-based routers deployed globally, all potentially exposed where CDP is enabled | |
| CVE-2020-3119 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary c A vulnerability in the Cisco Discovery Protocol implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability exists because the Cisco Discovery Protocol parser does not properly validate input for certain fields in a Cisco Discovery Protocol message. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. An successful exploit could allow the attacker to cause a stack overflow, which could allow the attacker to execute arbitrary code with administrative privileges on an affected device. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 8.8 | 5% |
| — | ||
| CVE-2020-3120 | A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthent A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software processes Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to exhaust system memory, causing the device to reload. Cisco Discovery Protocol is a Layer 2 protocol. To exploit this vulnerability, an attacker must be in the same broadcast domain as the affected device (Layer 2 adjacent). NVD description · AI analysis pending | 6.5 | 2% |
| — |
Full article604 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalFeb 05, 2020
Several Cisco-manufactured network equipments have been found vulnerable to five new security vulnerabilities that could allow hackers to take complete control over them, and subsequently, over the enterprise networks they power.
Four of the five high-severity bugs are remote code execution issues affecting Cisco routers, switches, and IP cameras, whereas the fifth vulnerability is a denial-of-service issue affecting Cisco IP phones.
Collectively dubbed 'CDPwn,' the reported vulnerabilities reside in the various implementations of the Cisco Discovery Protocol (CDP) that comes enabled by default on virtually all Cisco devices and can not be turned OFF.
Cisco Discovery Protocol (CDP) is an administrative protocol that works at Layer 2 of the Internet Protocol (IP) stack. The protocol has been designed to let devices discover information about other locally attached Cisco equipment in the same network.
According to a report Armis research team shared with The Hacker News, the underlying CDP implementations contain buffer overflow and format string vulnerabilities that could let remote attackers on the same network execute arbitrary code on the vulnerable devices by sending malicious unauthenticated CDP packets.
The list of CDPwn Cisco vulnerabilities affecting tens of millions of devices widely deployed in enterprise networks is as follow:
- Cisco NX-OS Stack Overflow in the Power Request TLV (CVE-2020-3119)
- Cisco IOS XR Format String vulnerability in multiple TLVs (CVE-2020-3118)
- Cisco IP Phones Stack Overflow in PortID TLV (CVE-2020-3111)
- Cisco IP Cameras Heap Overflow in DeviceID TLV (CVE-2020-3110)
- Cisco FXOS, IOS XR, and NX-OS Resource Exhaustion in the Addresses TLV (CVE-2020-3120)
To be noted, since CDP is a Data Link layer 2 protocol that can't cross the boundaries of a local area network, an attacker first needs to be on the same network to leverage CDPwn vulnerabilities.
However, after gaining an initial foothold in a targeted network using separate vulnerabilities, attackers can exploit CDPwn against network switches to break network segmentation and move laterally across the corporate networks to other sensitive systems and data.
"Gaining control over the switch is useful in other ways. For example, the switch is in a prime position to eavesdrop on network traffic that traverses through the switch, and it can even be used to launch man-in-the-middle attacks on the traffic of devices that traverses through the switch," the researchers said.
"An attacker can look to move laterally across segments and gain access to valuable devices like IP phones or cameras. Unlike switches, these devices hold sensitive data directly, and the reason to take them over can be a goal of an attacker, and not merely a way to break out of segmentation."
Additionally, CDPwn flaws also allow attackers to:
- Eavesdrop on voice and video data/calls and video feed from IP phones and cameras, capture sensitive conversations or images.
- Exfiltrate sensitive corporate data flowing through the corporate network's switches and routers.
- Compromise additional devices by leveraging man-in-the-middle attacks to intercept and alter traffic on the corporate switch.
Besides releasing a detailed technical report on the issues, the Armis research team has also shared videos of explanation and demonstration of the flaws, as embedded above.
After closely working with Armis researchers over the last few months to develop security patches, Cisco today released software updates for all of its affected products.
Though Cisco has also provided some mitigation information, affected administrators are still highly recommended to install the latest software updates to completely protect their valuable networks against malware and emerging online threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/02/cisco-cdp-vulnerabilities.html