HomeSecurityVulnerability in Cisco products allows backdoor installation

Vulnerability in Cisco products allows backdoor installation

backdoor

A new serious vulnerability, discovered in Cisco, allows malicious actors to install backdoors in wide-ranging devices used in enterprise and government networks, including servers, switches, and firewalls.

The vulnerability discovered by researchers at Red Balloon and identified as CVE-2019-1649, has been named Thrangrycat and affects many Cisco products that support the Trust Anchor module (TAm).

The Trust Anchor module (TAm) is a hardware-based Secure Boot feature implemented in almost all Cisco enterprise devices since 2013 and ensures that the firmware running on hardware platforms is authentic and unmodified.

However, as the researchers found, there are several flaws in the hardware design that could allow a capable attacker to modify the Trust Anchor module by modifying the FPGA bitstream and load a malicious bootloader.

Since exploiting this vulnerability requires root privileges, Cisco emphasized that only a local attacker with physical access to the targeted system could carry out such an attack.

However, Red Balloon researchers said that would-be hackers could exploit this vulnerability remotely, combining it with other flaws that could allow them to gain root access or at least execute root commands and install a backdoor.

To provide a glimpse into the specific attack, the researchers presented an RCE vulnerability (CVE-2019-1862) in the web user interface of Cisco's IOS operating system, which allows a logged-in administrator to remotely execute arbitrary commands in the underlying Linux shell of an affected device with root privileges.

After gaining root access, the administrator can remotely bypass the Trust Anchor module (TAm) using the Thrangrycat vulnerability and install a malicious backdoor.

According to the researchers, what makes the attack more serious is that by following the above procedure, the attacker can remotely bypass Cisco's secure boot mechanism and lock down all future software updates on the TAm.

Also, since the flaws are within the hardware design, it is unlikely that any software security patch will fully resolve the fundamental vulnerability.

Hundreds of millions of Cisco units using FPGA-based TAm around the world are vulnerable due to this vulnerability.

Red Balloon Security disclosed the issues to Cisco in November 2018, and only some details became public after Cisco released firmware patches to address the two flaws and list all affected products.

Cisco said the company has not detected any attacks that have exploited either of these two vulnerabilities.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS