Cisco issued a patch for a critical bug in its IOS XE operating system that could allow a remote attacker to bypass authentication on devices running the software.
The vulnerability, called CSCvn93524, ranked an impressive 10 out of 10 for severity. It’s found in the REST API virtual service container for Cisco IOS XE software. And it stems from an improper check performed by the area of code that manages the REST API authentication service.
Cisco found the critical bug during internal security testing. The company’s Product Security Incident Response Team says it’s “not aware of any public announcements or malicious use of the vulnerability.”
Here’s how it works. Attackers could exploit this flaw to obtain the token-id of an authenticated user. Once they had this token-id, they could use it to execute privileged actions through the interface of the REST API virtual service container on the affected device.
The threat researcher say affected products include: Cisco 4000 Series Integrated Services Routers, Cisco ASR 1000 Series Aggregation Services Routers, Cisco Cloud Services Router 1000V Series, and Cisco Integrated Services Virtual Router. The vulnerability does not affect Cisco IOS Software, Cisco IOS XR Software, or Cisco NX-OS Software.
While the bug exists in the Cisco REST API virtual service container, if exploited it affects devices running IOS XE. However, it only affects the device if it’s running the REST API interface, which is not enabled by default and must be installed and activated separately on IOS XE devices.
Cisco released a fixed version of the REST API virtual service container as well as a hardened version of the IOS XE software release that prevents installation or activation of a vulnerable container on a device. There are no known workarounds for this vulnerability.
The vendor in late June patched two critical security flaws in its Data Center Network Manager software that could allow attackers to take over affected devices. And that patch followed a particularly buggy May that included Thrangrycat, which was a vulnerability found in “tens of millions” of Cisco enterprise routers, switches, and firewalls that could allow hackers to remotely attack corporate networks, steal data, and attack other devices connected to the networks.
Comments