SECURITY
SECURITY
SECURITY
Cisco Systems Inc. is urging customers to update affected routers quickly after the discovery and disclosure of a severe vulnerability on devices running its IOS XE operating system.
CVE-2019-12643, as it’s known, ranked as a 10 out 10 for severity. The vulnerability in the Cisco REST API virtual service container for Cisco IOS XE, revealed Wednesday, can allow an attacker to bypass authentication on a managed Cisco IOS XE device.
The vulnerability is said to be the result of an improper check performed in an area of code that manages the REST API authentication service. It affects Cisco 400 Series Integrated Services Routers, Cisco ASR 1000 Series Aggregation Service Routers, Cisco Cloud Services Router 1000V Series and Cisco Integrated Services Virtual Router.
“The critical authentication bypass flaw in Cisco IOS XE could be exploited by an unauthenticated, remote attacker sending specially crafted HTTP requests to a vulnerable device, resulting in the exposure of an authenticated users’ token-id,” Scott Caveza, research engineering manager at cyber exposure firm Tenable Inc., told SiliconANGLE.
“While the flaw is critical, it’s important to note there are a number of requirements for successful exploitation, including the device has both installed and enabled an affected version of the Cisco REST API virtual service container,” Ceveza explained. “In addition, a user must be logged into the device in order to obtain the token I.D.”
Chetan Conikee, chief technology officer of appsec automation company ShiftLeft Inc., noted that “the flaw is a reminder that application security needs to extend to every piece of code that exists in an organization’s network.
“API dependencies serve an important purpose, in that they enable each development organization to focus on the code for which they add the most value and leverage the innovation of other organizations by leveraging their APIs,” he said. “But by integrating the API into your application, you also inherit its vulnerabilities.”
Cisco has released iosxe-remote-mgmt.16.03.03.ova, a updated version of the virtual service container, as well as added additional safeguards in updated IOS XE versions. The updates are available to licensed users only.
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.