Cisco Details IOS Vulnerability Spilled At Black Hat - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

02:51 PM

Cisco Details IOS Vulnerability Spilled At Black Hat

Even as Cisco admitted to the problems, Symantec warned that the information shared at the conference "increases the threat of exploitation."

The impact of the Black Hat presentation on Cisco continued to spread Friday as Symantec warned customers that the information spilled at the conference "increases the threat of exploitation," and Cisco finally published an advisory alerting its users about the vulnerability leveraged in the exploit demonstration.

Michael Lynn, a researcher for Internet Security Systems (ISS) who resigned from his post to present his findings at the security conference, outlined how new exploitation techniques could be applied to old vulnerabilities to seize control of Cisco routers or render them inoperative. Cisco's hardware plays a dominant role in the Internet's infrastructure, and any mass attack on its routers could cripple the Net.

While it hasn't had a chance to confirm Lynn's claims -- and may never, now that a gag order has been placed on both the Black Hat conference and Lynn from further discussion -- Symantec's alert noted that the disclosure "represents a potentially significant threat against existing infrastructure currently deployed."

Symantec went on to explain that attackers may be able to "more reliably exploit vulnerabilities against Cisco IOS (Internetwork Operating System, the OS that runs Cisco's routers and some of its switches) that may have been thought to be extremely difficult or unreliable."

Some already-uncovered vulnerabilities that were earlier thought to be "low risk" may now to exploitable, Symantec concluded.

It recommended that enterprises do an immediate audit of existing vulnerabilities in their Cisco hardware and apply the associated patches ASAP.

For its part, Cisco was adamant that Lynn's demonstrated exploit technique didn't take advantage of a new vulnerability, but instead was only a new and different angle that could be used on existing flaws. The vulnerability Lynn used, said Cisco, was one discovered and patched in April, although customers were never told why the patches had been issued.

On Friday, Cisco disclosed details of that April vulnerability by issuing a security advisory.

According to the advisory, IOS is vulnerable to a denial-of-service (DoS) attack, and possibly to a much more dangerous exploit that could actually introduce hacker code remotely, via a specially-crafted IPv6 packet.

"Lynn did not disclose a new vulnerability," said Cisco spokesman John Noh. "But this advisory relates to the vulnerability he discussed at Black Hat."

Alfred Huger, vice president of engineering for Symantec’s security response team, confirmed that the vulnerability outlined in the Cisco advisory was the same as the one Lynn used Wednesday during his demonstration.

"They are indeed one and the same," Huger said.

While patches for IOS were issued in April for the bug, Cisco "did not issue an advisory at that time, because we have a very clear set of guidelines for disclosing vulnerabilities and when to issue an advisory," Noh added.

Before Cisco believes an advisory is merited, one of three conditions must be met, said Noh. Those include an available fix or patch, confirmation of an active exploit, or what he called a "heightened sense of public awareness."

"That last one was met with the disclosures at Black Hat," Noh said.

In the advisory, Cisco noted that all its devices -- primarily routers -- which run "any unfixed version of IOS code that supports, and is configured for, IPv6" is vulnerable. An attack, however, relies on a maliciously-crafted IPv6 packet that must be sent from a local network segment. "This vulnerability can not be exploited one or more hops from the IOS device," Cisco said. In other words, the attacker would have to have access to a machine inside the perimeter, possibly a previously-compromised computer or device.

Cisco posted a long list of the fixed versions of IOS that users could migrate to if they haven't already done so, as well as a work-around for those unable to patch. That work-around is disable IPv6 processing on devices when the protocol isn't needed.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
The State of IT & Cybersecurity Operations 2020
The State of IT & Cybersecurity Operations 2020
Download this report from InformationWeek, in partnership with Dark Reading, to learn more about how today's IT operations teams work with cybersecurity operations, what technologies they are using, and how they communicate and share responsibility--or create risk by failing to do so. Get it now!
10 Cyberattacks on the Rise During the Pandemic
Cynthia Harvey, Freelance Journalist, InformationWeek,  6/24/2020
IT Trade Shows Go Virtual: Your 2020 List of Events
Jessica Davis, Senior Editor, Enterprise Apps,  5/29/2020
Study: Cloud Migration Gaining Momentum
John Edwards, Technology Journalist & Author,  6/22/2020
Register for InformationWeek Newsletters
Current Issue
Key to Cloud Success: The Right Management
This IT Trend highlights some of the steps IT teams can take to keep their cloud environments running in a safe, efficient manner.
White Papers
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Sponsored Video
Flash Poll