UPDATED 22:56 EST / AUGUST 29 2019

SECURITY

Update now: Cisco releases patch to address critical vulnerability in IOS XE devices

Cisco Systems Inc. is urging customers to update affected routers quickly after the discovery and disclosure of a severe vulnerability on devices running its IOS XE operating system.

CVE-2019-12643, as it’s known, ranked as a 10 out 10 for severity. The vulnerability in the Cisco REST API virtual service container for Cisco IOS XE, revealed Wednesday, can allow an attacker to bypass authentication on a managed Cisco IOS XE device.

The vulnerability is said to be the result of an improper check performed in an area of code that manages the REST API authentication service. It affects Cisco 400 Series Integrated Services Routers, Cisco ASR 1000 Series Aggregation Service Routers, Cisco Cloud Services Router 1000V Series and Cisco Integrated Services Virtual Router.

“The critical authentication bypass flaw in Cisco IOS XE could be exploited by an unauthenticated, remote attacker sending specially crafted HTTP requests to a vulnerable device, resulting in the exposure of an authenticated users’ token-id,” Scott Caveza, research engineering manager at cyber exposure firm Tenable Inc., told SiliconANGLE.

“While the flaw is critical, it’s important to note there are a number of requirements for successful exploitation, including the device has both installed and enabled an affected version of the Cisco REST API virtual service container,” Ceveza explained. “In addition, a user must be logged into the device in order to obtain the token I.D.”

Chetan Conikee, chief technology officer of appsec automation company ShiftLeft Inc., noted that “the flaw is a reminder that application security needs to extend to every piece of code that exists in an organization’s network.

“API dependencies serve an important purpose, in that they enable each development organization to focus on the code for which they add the most value and leverage the innovation of other organizations by leveraging their APIs,” he said. “But by integrating the API into your application, you also inherit its vulnerabilities.”

Cisco has released iosxe-remote-mgmt.16.03.03.ova, a updated version of the virtual service container, as well as added additional safeguards in updated IOS XE versions. The updates are available to licensed users only.

Image: Cisco

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU