Five newly discovered zero-day vulnerabilities in Cisco Discovery Protocol (CDP) that affect tens of millions of Cisco enterprise devices could allow attackers to remotely takeover these devices without any user interaction, according to IoT security company Armis.

Armis found the bugs and said it worked with Cisco over the last few months to develop patches. Today, Cisco notified customers and issued patches for all five high-impact vulnerabilities. Cisco says it's not aware of malicious use of any of the five vulnerabilities.

CDP is a Cisco proprietary Layer 2 network protocol that is used to discover information about locally attached Cisco equipment. This aids in mapping the presence of other Cisco products in the network. Most Cisco products use CDP and the five vulnerabilities affect a slew of Cisco products including IP phones, surveillance cameras, switches, routers, interconnects, and security appliances. Two of the bugs also affect white-box routers if they have CDP enabled.

Armis estimates the Cisco bugs, collectively called CDPwn, could allow an attacker to remotely take over tens of millions of devices. Four of the Cisco zero-day vulnerabilities are critical remote code execution (RCE) vulnerabilities and one is a denial of service (DoS) vulnerability. If exploited, these would allow an attacker to eavesdrop on voice and video calls and feeds from IP phones and cameras, and also steal corporate data flowing through the network’s switches and routers.

Breaking Network Segmentation

Armis says the attackers could also use the vulnerabilities to break network segmentation, thus allowing them to move laterally across networks and access other sensitive systems and data, as well as to leverage man-in-the-middle attacks to intercept and alter network traffic on the switch.

“Increasingly, these devices can, and do, connect to the enterprise network. And large numbers of these devices end up in places that attackers find extremely valuable,” said Ben Seri, VP of Research at Armis, in a statement. “The findings of this research are significant as Layer 2 protocols are the underpinning for all networks, and as an attack surface are an under-researched area and yet are the foundation for the practice of network segmentation.”

This is important because many companies use network segmentation to provide security. However, this research shows that network segmentation does not guarantee security, Seri said.

Last month Insight Partners reached a deal to acquire Armis for $1.1 billion. It’s the largest-ever enterprise IoT security software acquisition, according to the companies.