Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released



Cisco published new advisories for Integrated Management Controller (IMC) and Unified Computing System (UCS) Director, and updates for Small Business 220 Series Smart Switches that include the existence of public exploit code. 

背景

On August 21, Cisco published 27 new advisories and updated six advisories across a variety of its products.

分析

Twelve of the advisories address vulnerabilities in Cisco Integrated Management Controller (IMC) used to manage Cisco Unified Computing System (UCS) C-Series Rack Servers and S-Series Storage Servers. Six advisories are for vulnerabilities affecting Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data. Four of the six advisories are rated by Cisco as Critical.

CVE产品Impact 类型 CVSSv3 (Vendor) 严重性
CVE-2019-1938Cisco UCS Director and Cisco UCS Director Express for Big Data APIAuthentication BypassUnauthenticated9.8严重
CVE-2019-1935Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big DataUser Default CredentialsUnauthenticated9.8严重
CVE-2019-1937Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big DataAuthentication BypassUnauthenticated9.8严重
CVE-2019-1974Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big DataAuthentication BypassUnauthenticated9.8严重
CVE-2019-12634Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big DataCommand InjectionUnauthenticated8.6
CVE-2019-1936Cisco IMC Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big DataCommand InjectionAuthenticated7.2

Five of the six vulnerabilities could be exploited by an unauthenticated, remote attacker sending specially crafted requests to a vulnerable system. CVE-2019-1936 can only be exploited by an authenticated, remote attacker who is capable of logging into the vulnerable management interface. However, with CVE-2019-1935, an attacker could exploit this vulnerability by using the ‘scpuser’ account. According to Cisco, this default account has “incorrect permission settings” and uses an “undocumented default password” to log into a vulnerable system. Tenable has not yet confirmed whether use of the scpuser account would allow an attacker to exploit CVE-2019-1936.

Cisco also patched several additional IMC vulnerabilities this month.

CVEImpactCVSSv3 严重性
CVE-2019-1907权限提升8.8
CVE-2019-1865Command Injection8.8
CVE-2019-1864Command Injection8.8
CVE-2019-1900Denial of Service7.5
CVE-2019-1908Information Disclosure7.5
CVE-2019-1896Command Injection7.2
CVE-2019-1885Command Injection7.2
CVE-2019-1634Command Injection7.2
CVE-2019-1850Command Injection7.2
CVE-2019-1871Buffer Overflow7.2
CVE-2019-1883Command Injection7.0
CVE-2019-1863权限提升6.5

In addition to these new advisories, Cisco released several updates for previously published advisories. This includes updates to the recently reported vulnerabilities in the Cisco Small Business 220 Series Smart Switches from August 6.

CVEImpactCVSSv3Tenable VPR 严重性
CVE-2019-1913Remote Code Execution9.88.9严重
CVE-2019-1912Authentication Bypass9.18.3严重
CVE-2019-1914Command Injection7.28.6中危

Two of the three 220 Series Smart Switches vulnerabilities are rated as Critical and exist within the web management interface of these devices. Sending specially crafted requests to the vulnerable interface could allow a remote attacker to execute arbitrary code (CVE-2019-1913) or modify the device configuration (CVE-2019-1912). CVE-2019-1914 requires an attacker to be authenticated on a vulnerable interface and have level 15 permissions.

Additionally, Cisco updated its advisory for CVE-2019-1649, the Secure Boot Hardware Tampering Vulnerability known as Thrangrycat, to account for additional vulnerable products.

概念验证

Cisco’s Product Security Incident Response Team (PSIRT) notes in the updated advisories for the Small Business 220 Series Smart Switches that they are aware of the presence of public exploit code for these devices. However, at the time this blog post was published, Tenable has not identified a proof of concept (PoC) for these vulnerabilities.

解决方案

Cisco has released updates for each of the affected products. The affected versions and relevant fixed versions can be found under the advisory pages. Customers should obtain and install these updates as soon as possible.

识别受影响的系统

用于识别这些漏洞的 Tenable 插件列表在发布时将显示在此处

Get more information 

加入 Tenable Community 中的 Tenable 安全响应团队

了解有关 Tenable 这款首创 Cyber Exposure 平台的更多信息,全面管理现代攻击面。

Get a free 60-day trial of Tenable.io Vulnerability Management.


您可加以利用的网络安全新闻

输入您的电子邮件,绝不要错过 Tenable 专家的及时提醒和安全指导。