Trellix today announced it found two “notable” vulnerabilities that impact a range of Cisco networking devices, and that one of the bugs might serve as a potential hardware supply chain risk.

The Trellix Advanced Research noted it discovered a command injection (CVE-2023-20076) and a path traversal (Cisco bug ID CSCwc67015) bug in a Cisco ISR 4431 router. Those two vulnerabilities also affect Cisco’s other devices, including 800-Series Industrial ISRs, CGR1000 Compute Modules, IC3000 Industrial Compute Gateways, IOS XE-based devices configured with IOx, IR510 WPAN Industrial Routers, and Cisco Catalyst Access Points (COS-APs).

Researchers noted in a blog post that the CVE-2023-20076 bug could allow attackers to gain almost complete control over the affected device's operating system and allows administrators to deploy application containers or virtual machines (VMs) directly on the device. This command injection can bypass the mitigations Cisco has in place through reboots and system resets.

“CVE-2023-20076 gains unrestricted access, allowing malicious code to lurk in the system and persist across reboots and firmware upgrades,” Trellix researchers wrote. “If an attacker exploits this vulnerability, the malicious package will keep running until the device is factory reset or until it is manually deleted.”

As many businesses outsource the configuration and network design to third-party installers, this exploitation might also have a supply chain impact, researchers warned. “A bad actor could use CVE-2023-20076 to maliciously tamper with one of the affected Cisco devices anywhere along this supply chain.”

The other bug was also discovered in the application hosting environment. The CSCwc67015 flaw is an exploitable version of the Python tarfile vulnerability Trellix disclosed last year, the team noted. Researchers found a maliciously packed application could bypass a vital security check while uncompressing the uploaded application.

What Should Users Do?

Trellix reported the vulnerabilities to Cisco and claims the networking giant was a partner in the research and disclosure process.

Trellix recommends organizations who are using the affected devices should update to the latest firmware immediately and check if any abnormal containers were installed or running in their environment. And those who don’t use containers should disable the IOx container framework.

Cisco also released a security advisory and patch information for the vulnerabilities.