HomeSecurityCisco warns of a password flaw in the Network Assurance Engine

Cisco warns of a code flaw in the Network Assurance Engine

Cisco is warning its customers that they must immediately install an update that will fix a very serious issue affecting the Network Assurance Engine (NAE) for data-center network management.

Cisco

More specifically, the bug was identified as CVE-2019-1688 and could essentially allow an attacker to exploit this flaw in password to hit an NAE server and cause a denial-of-service attack.

For those who don't know, NAE is an important data-center network management tool that helps administrators evaluate the effects of network changes and avoid application.

As Cisco explains, the flaw occurred due to changes in user passwords, as the web-management interface fails to propagate to the command-line interface (CLI), leaving the old password default in place in the CLI. It should be noted that this issue only affects NAE version 3.0 so that older versions are not affected. A local attacker could exploit the flaw by validating the default administrator password in the CLI of an affected server. From that point, the attacker could view sensitive information and take down the server.

However, there is no need to worry anymore, as Cisco has made corrections but the contribution of each customer is also necessary. Specifically, the company has published an upgrade "NAE Release 3.0" which all customers must install and at the same time the administrator passwords must be changed after upgrading to the latest release.

In addition to these, Cisco has also provided another workaround for this bug, which involves changing the default administrator password from the CLI. However, Cisco has suggested that customers contact the company's technical support center to perform the aforementioned method so that the default password can be entered into a secure remote-support session. Fortunately, Cisco's security team is not aware of any live attacks that exploit the bug, which was discovered during internal security audits.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS