HomeSecurityCisco Elastic Services Controller: Patches released for critical vulnerability

Cisco Elastic Services Controller: Patches released for critical vulnerability

Cisco has released a new security update with fixes for a critical vulnerability found in the Cisco Elastic Services Controller REST API allowing remote full control of the system.

Cisco Elastic Services Controller is a virtual network operations managerthat enables enterprises to automate the deployment and monitoring of operations running in their virtual environment.

Cisco

This critical vulnerability affected Cisco Elastic Services Controllers running Software Release 4.1, 4.2, 4.3, or 4.4 when the REST API is enabled by default.

Essentially, the vulnerability affected the controller due to malformed API requests.

A successful exploit allows the hacker to perform arbitrary actions via the REST API with administrator privileges on an affected system.

Below is the table with the patches released according to Cisco's report.

Cisco Elastic Services Controller Major ReleaseSoftware Releases with Available Patches
Before 4.1Not vulnerable
4.14.1.0.100
4.1.0.111
4.24.2.0.74
4.2.0.86
4.34.3.0.121
4.3.0.128
4.3.0.134
4.3.0.135
4.44.4.0.80
4.4.0.82
4.4.0.86
4.5Not vulnerable

 

Check if REST API is enabled. Administrators can check if REST API is enabled or not by running the following command on the ESC sudo netstat -tlnup | grep '8443 | 8080'

Once the command is successfully executed, the following example shows the command output for a machine that has the REST API service enabled on port 8443.

 

~ / # sudo netstat -tlnup | grep '8443 | 8080'

.

.

.

tcp6 0 0 ::: 8443 ::: * LISTEN 2557 / java

This vulnerability was found during internal security testing. It was named CVE-2019-1867.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS