Cisco issued 31 security advisories this week, but focused users' attention on "critical" patches for IOS and IOS XE Software Cluster Management and IOS software for Cisco ASR 9000 Series routers. Several other vulnerabilities also need attention if clients are using Cisco wireless LAN controllers.

The first critical patch addresses a vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE that could allow an unauthenticated remote attacker to send malformed CMP settings during a Telnet session with a Cisco device configured to accept such connections. An exploit could allow an attacker to execute arbitrary code and gain complete control of the device or cause the device to reboot.
According to the company, the cluster management protocol uses Telnet internally as a signaling and command protocol between cluster members. The vulnerability is caused by a combination of two factors:
Failure to restrict the use of CMP Telnet options to only internal local communications between cluster members and to accept such settings over any Telnet connection to a device.
Incorrect processing of malformed CMP Telnet settings.
Cisco says the vulnerability can be identified during Telnet connection validation over IPv4 or IPv6. Sending malformed settings in Telnet sessions through the device is not a vulnerability.
The company says there are no workarounds for this issue, but disabling Telnet as an allowed protocol for incoming connections would eliminate the exploit factor. Cisco recommends disabling Telnet and replacing it with the SSH protocol. Information on how to do both can be found in Cisco's guide for Cisco IOS devices.
The second critical patch addresses a vulnerability in the sysadmin virtual machine (VM) in Cisco's ASR 9000 carrier-class routers running Cisco IOS XR 64-bit software. The software could allow a remote attacker to access internal applications running in the sysadmin VM.
The company said the vulnerability is due to incorrect isolation of the secondary management interface from internal sysadmin applications. An attacker could exploit this vulnerability if they were to connect to one of the internal applications. A successful attack could lead to unstable conditions, including both denial of service (DoS) and remote unauthorized access to the device.
Finally, Cisco wrote that several vulnerabilities in the GUI configuration function for the Cisco Wireless LAN Controller (WLC) software could allow an authorized remote attacker to force the device to reboot unexpectedly during device configuration when the administrator uses this GUI on a device. The attacker would need to have valid administrator credentials on the device for this exploit to work, Cisco said.
“These vulnerabilities are due to incomplete input validation for improper configuration settings that an attacker could submit when accessing the GUI configuration menus. An attacker could exploit these vulnerabilities by authenticating the device and submitting information from users when using the administrative GUI functional configuration,” Cisco said, adding, “These vulnerabilities have been marked as ‘high risk’ because they could be exploited when security updates are not installed.”.
The company has released software updates that address these vulnerabilities and said there are no other workarounds for the issue.
