HomeSecurityCisco removes backdoor from some of its access points

Cisco removes backdoor from some of its access points

After finding hardcoded credentials and removing them from Juniper and Fortinet networking products, now it's Cisco's turn to patch its devices and remove a backdoor account.

Yesterday, Cisco released several updates aimed at fixing a number of flaws in its products. Among the five releases, one stood out, especially after the recent revelation of backdoors in networking products belonging to some of Cisco, Juniper and Fortinet.

Cisco removes backdoor from some of its access points

The vulnerability (CVE-2015-6336) is related to an account in Cisco's Aironet 1800 series access points, which would allow an attacker to gain access to the devices, via a series of hardcoded credentials, for the device's firmware.

Cisco account did not provide full administrator privileges on the device, but would allow an attacker access anyway.

The Cisco Aironet 1830e, 1830i, 1850e, and 1850i were affected by this issue, for which the company offered a software update to remove the account.

Last December, after Juniper revealed the presence of a backdoor in its ScreenOS operating system installed on firewall equipment, Cisco launched a thorough corporate audit to look for similar issues.

But that wasn't Cisco's biggest problem, as the company also fixed two very critical security vulnerabilities, both with an overall score of 10 out of 10 on the CVSS severity scale.

The first (CVE-2015-6314) affects all devices running Cisco Wireless LAN Controller (WLC) software, versions 7.6.120.0 and later, 8.0 and later, or 8.1 and later. This vulnerability could allow a remote attacker to access the device and its configuration settings.

The second vulnerability (CVE-2015-6323), also with a severity score of 10 out of 10, is a vulnerability in the administrator portal of devices running Cisco Identity Services Engine (ISE) (affecting versions 1.1 and later, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, or 1.4 before patch 4).

This allows a remote attacker to gain unauthorized access to affected devices as well as modify the device configuration.

"A successful exploit could completely compromise the device," Cisco of the two flaws.

Since Cisco announced that there are no techniques or settings that can be implemented to mitigate these flaws, system administrators are urged to patch their Cisco products as soon as possible.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS