5 ms·
Cisco buffer overflow vulnerability with remote code execution
- silenteh 11y agoHere a nice explanation of the vulnerability: https://blog.exodusintel.com/2016/02/10/firewall-hacking/ https://blog.exodusintel.com/2016/02/10/firewall-hacking/ There is also a Snort signature to detect attempts to exploit this vulnerability.
- deleted 11y ago[deleted]
- tyingq 11y agoEdit...this is wrong-> It's specific to Cisco ASA firewalls with a version level < 9.1(7), which was released in January of 2015. Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.
- EwanG 11y agoGiven the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.
- feld 11y agoPeople who have firewall needs and no skills hire people who know what Cisco products are, get someone to implement an ASA for them, and then it sits for years without any software updates. Maybe a rule update every now and then, but definitely no software updates.
- code777777 11y agoPerhaps most do but I see a different trend these days. "The network" is a lot more important now since so many things are cloud-based. Our networking group automated a deployment for the fix and contacted everyone that has ever bought an ASA from our company and updated them. We have ~400 ASAs across the country still have < 50 to go. There are still a few stragglers and the older ASAs need a bit more TLC. Many of those clients have a maintenance agreement with us that includes these sorts of things and changes. All of them were updated and tested within 24 hours. We did the same thing for the Juniper exploits (albeit we only had a handful). EDIT: typos
- kjs3 11y agoI can think of at least 8 of my clients (between 500 and 15000 employees, with probably 100 ASAs total) still on ASA version 8, much less 9. For some, the more critical in infrastructure, the less they want to update.
- qwijibo 11y agokjs3 - you replied to this and are hellbanned here, as am I apparently.
- Gelob 11y agoThat isn't true. There are versions of 9.2.x, 9.3.x etc that are vulnerable per the documentation. 9.1.7 is the only firmware released before this was announced (jan 18th) that contains a fix. Every other software version is vulnerable and requires an upgrade.
- madsushi 11y agoCisco was also rushed to release the fix, as all of the new builds are tagged 'interim' and warn users that they have bugs and stability problems that will be fixed later. Most notably, several issues with ASA Clustering were found in the new builds. So you're damned if you do, damned if you don't.
- achillean 11y agoHere's an overview of devices that are running IKE on the Internet at the moment: https://www.shodan.io/report/h2Naw1fd https://www.shodan.io/report/h2Naw1fd
- virtualwhys 11y ago> Note: Only traffic directed to the affected system can be used to exploit this vulnerability. I'm confused, how else would the system be compromised, by directing traffic at the moon? Running an EOL ASA in colo on v8.2. Have been holding out due to the post-v8.2 changes to NAT. Looks like you need a SmartNET contract to get the fix, unfortunate, many legacy devices will left vulnerable as a result. Well, there goes the weekend...
- alt219 11y agoIt does seem that Cisco will provide updates if customers don't have a valid SmartNET contract. From the vulnerability disclosure: > Customers Without Service Contracts > Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco Technical Assistance Center (TAC): http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html http://www.cisco.com/en/US/support/tsd_cisco_worldwide_conta... > Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.
- virtualwhys 11y agoThanks, I missed that, just followed: > Products > Security > Firewalls > Adaptive Security Appliances (ASA) > ASA 5500-X Series Firewalls > <your Cisco ASA model> > Software on Chassis > Adaptive Security Appliance (ASA) Software and was prompted that an active service contract is required. Not that I'm opposed, it's the first thing I'll do prior to upgrading (since 8.2 to 8.3 migration looks non-trivial due to NAT changes, and have no clue what has transpired between 8.3. and 9.1). Of course this is obviously a sign to just upgrade the hardware and get off the EOL train.
- EvanKelly 11y agoI think they're suggesting that someone snooping the encrypted traffic coming from the ASA couldn't leverage this vulnerability for easier decryption. (i.e. this is an active, not passive vulnerability). That's probably clear when they say it allows RCE, but who knows.
- SpyKiIIer 11y agoRackspace pushed this update to all their clients last night, as they have seen this attack against some of their infrastructure...
- xyzzy4 11y agoAs someone who used to work at Cisco, I'm not surprised. Everything is coded in C, and there are memory leaks all over the place because releases are made before most of these bugs are fixed.