[This story was updated on 4/10/18 with Cisco's comments] Cisco is urging organizations to immediately address a critical flaw in its network switches running IOS and IOS XE software amid reports of widespread attacks against the devices in several countries. The company on Monday published a security advisory on the remote code execution flaw (CVE-2018-0171) in the Smart Install function in Cisco IOS and IOS XE software. Cisco described the flaw — first disclosed March 29 by Embedi — as an issue that could allow an unauthenticated remote attacker to trigger a denial-of-service condition or to execute code of their choice on an affected device. Emedi on March 29 claimed it had found some 250,000 network devices that were vulnerable to the issue. The RCE flaw is separate from a protocol misuse issue also related to the Smart Install function that Cisco first issued an advisory about on Feb 14, 2017 and has updated a couple of times. It is apparently the protocol misuse issue that attackers have been exploiting in the recent attacks, not the RCE flaw. However, Cisco has urged organizations to address both issues immediately, citing widespread and ongoing attacks against its switches in multiple countries. "While we have only observed attacks leveraging the protocol misuse issue, recently, another vulnerability in the Cisco Smart Install Client was disclosed and patched," the company said in a blog. "While mitigating the protocol misuse issue, customers should also address this ...
Attackers Exploit Cisco Switch Issue as Vendor Warns of Yet Another Critical Flaw
Dark Reading
·Published Apr 9, 2018
·Updated
Affected Software
2 affected components
Cisco IOS=IOS and IOS XE software
Cisco IOS XE=IOS and IOS XE software
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Cisco network switches running IOS and IOS XE software that is being actively exploited by attackers.
2
What security implications are discussed?
The article highlights the urgency for organizations to patch their devices to prevent exploitation of the critical flaw.
3
What products or software are affected?
The affected products include Cisco network switches running IOS and IOS XE software.
4
When was the critical flaw identified by Cisco?
The critical flaw was reported by Cisco on April 9, 2018.
5
What should organizations do in response to this vulnerability?
Organizations are urged to immediately update their Cisco devices to mitigate the risk of exploitation.