• Cisco issues critical warning after CIA WikiLeaks dump bares IOS security weakne

    Home » Forums » Admin IT Lounge » Admin IT Lounge – Miscellaneous » Cisco issues critical warning after CIA WikiLeaks dump bares IOS security weakne

    Author
    Topic
    #102869

    Cisco issues critical warning after CIA WikiLeaks dump bares IOS security weakness
    Cisco says vulnerability in 300 models of Catalyst switches
    http://www.networkworld.com/article/3182871/security/cisco-issues-critical-warning-after-cia-wikileaks-dump-bares-ios-security-weakness.html

    By Michael Cooney
    Online News Editor, Network World | MAR 20, 2017 9:07 AM PT

    Credit: Ilya Pavlov/Unsplash
    Credit: Ilya Pavlov/Unsplash

    A vulnerability in Cisco’s widely deployed IOS software that was disclosed in the recent WikiLeaks dump of CIA exploits has triggered the company to release a critical warning for its Catalyst networking customers.

    +More on Cisco Security on Network World: Cisco security advisory dump finds 20 warnings, 2 critical+

    The vulnerability — which could let an attacker cause a reload of an affected device or remotely execute code and take over a device — impacts more than 300 models of Cisco Catalyst switches from the model 2350-48TD-S Switch to the Cisco SM-X Layer 2/3 EtherSwitch Service Module.

    Specifically, the vulnerability is contained in the Cluster Management Protocol which uses Telnet as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors Cisco said:

    ……..

    --------------------------------------

    1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB

    SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64

    CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
    Graphics Radeon RX 580, RX 580 ONLY Over Clocked
    More perishable

    2xMonitors Asus DVI, Sony 55" UHD TV HDMI

    1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
    1xOS W8.1 Pro, NAS Dependent, Same Sony above.

    -----------------

    Viewing 1 reply thread
    Author
    Replies
    • #102890

      Hundreds of Cisco switches vulnerable to flaw found in WikiLeaks files

      The flaw was found by Cisco security researchers, despite WikiLeaks’ claiming that the CIA hacking unit disclosures did not contain working vulnerabilities.
      http://www.zdnet.com/article/cisco-warns-of-critical-security-flaw-found-buried-in-wikileaks-vault-7-disclosure/

      By Zack Whittaker for Zero Day | March 20, 2017 — 16:56 GMT (09:56 PDT) | Topic: Security

      --------------------------------------

      1. Tower Totals: 2xSSD ~512GB, 2xHHD 20 TB, Memory 32GB

      SSDs: 6xOS Partitions, 2xW8.1 Main & Test, 2x10.0 Test, Pro, x64

      CPU i7 2600 K, SandyBridge/CougarPoint, 4 cores, 8 Threads, 3.4 GHz
      Graphics Radeon RX 580, RX 580 ONLY Over Clocked
      More perishable

      2xMonitors Asus DVI, Sony 55" UHD TV HDMI

      1. NUC 5i7 2cores, 4 Thread, Memory 8GB, 3.1 GHz, M2SSD 140GB
      1xOS W8.1 Pro, NAS Dependent, Same Sony above.

      -----------------

    • #102919

      Love the irony of the vulnerable Management Protocol being called the Cluster. Maybe they should add a few letters…

      Windows 10 Home 22H2, Acer Aspire TC-1660 desktop + LibreOffice, non-techie

      1 user thanked author for this post.
    Viewing 1 reply thread
    Reply To: Cisco issues critical warning after CIA WikiLeaks dump bares IOS security weakne

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: