Cisco has released a new security update with fixes for a critical vulnerability found in the Cisco Elastic Services Controller REST API allowing remote full control of the system.
Cisco Elastic Services Controller is a virtual network operations managerthat enables enterprises to automate the deployment and monitoring of operations running in their virtual environment.

This critical vulnerability affected Cisco Elastic Services Controllers running Software Release 4.1, 4.2, 4.3, or 4.4 when the REST API is enabled by default.
Essentially, the vulnerability affected the controller due to malformed API requests.
A successful exploit allows the hacker to perform arbitrary actions via the REST API with administrator privileges on an affected system.
Below is the table with the patches released according to Cisco's report.
| Cisco Elastic Services Controller Major Release | Software Releases with Available Patches |
| Before 4.1 | Not vulnerable |
| 4.1 | 4.1.0.100 4.1.0.111 |
| 4.2 | 4.2.0.74 4.2.0.86 |
| 4.3 | 4.3.0.121 4.3.0.128 4.3.0.134 4.3.0.135 |
| 4.4 | 4.4.0.80 4.4.0.82 4.4.0.86 |
| 4.5 | Not vulnerable |
Check if REST API is enabled. Administrators can check if REST API is enabled or not by running the following command on the ESC sudo netstat -tlnup | grep '8443 | 8080'
Once the command is successfully executed, the following example shows the command output for a machine that has the REST API service enabled on port 8443.
~ / # sudo netstat -tlnup | grep '8443 | 8080'
.
.
.
tcp6 0 0 ::: 8443 ::: * LISTEN 2557 / java
This vulnerability was found during internal security testing. It was named CVE-2019-1867.
