
A new serious vulnerability, discovered in Cisco, allows malicious actors to install backdoors in wide-ranging devices used in enterprise and government networks, including servers, switches, and firewalls.
The vulnerability discovered by researchers at Red Balloon and identified as CVE-2019-1649, has been named Thrangrycat and affects many Cisco products that support the Trust Anchor module (TAm).
The Trust Anchor module (TAm) is a hardware-based Secure Boot feature implemented in almost all Cisco enterprise devices since 2013 and ensures that the firmware running on hardware platforms is authentic and unmodified.
However, as the researchers found, there are several flaws in the hardware design that could allow a capable attacker to modify the Trust Anchor module by modifying the FPGA bitstream and load a malicious bootloader.
Since exploiting this vulnerability requires root privileges, Cisco emphasized that only a local attacker with physical access to the targeted system could carry out such an attack.
However, Red Balloon researchers said that would-be hackers could exploit this vulnerability remotely, combining it with other flaws that could allow them to gain root access or at least execute root commands and install a backdoor.
To provide a glimpse into the specific attack, the researchers presented an RCE vulnerability (CVE-2019-1862) in the web user interface of Cisco's IOS operating system, which allows a logged-in administrator to remotely execute arbitrary commands in the underlying Linux shell of an affected device with root privileges.
After gaining root access, the administrator can remotely bypass the Trust Anchor module (TAm) using the Thrangrycat vulnerability and install a malicious backdoor.
According to the researchers, what makes the attack more serious is that by following the above procedure, the attacker can remotely bypass Cisco's secure boot mechanism and lock down all future software updates on the TAm.
Also, since the flaws are within the hardware design, it is unlikely that any software security patch will fully resolve the fundamental vulnerability.
Hundreds of millions of Cisco units using FPGA-based TAm around the world are vulnerable due to this vulnerability.
Red Balloon Security disclosed the issues to Cisco in November 2018, and only some details became public after Cisco released firmware patches to address the two flaws and list all affected products.
Cisco said the company has not detected any attacks that have exploited either of these two vulnerabilities.
