HomeSecurityCisco breached through SaltStack server exploit

Cisco was breached via SaltStack server exploit

Cisco said today that some of its Cisco Virtual Internet Routing Lab Personal Edition (VIRL-PE) support servers were compromised by exploiting critical SaltStack vulnerabilities that were patched last month.

“Cisco infrastructure maintains the master-salt servers used with Cisco VIRL-PE,” a security advisory published earlier today states. “These servers were upgraded on May 7, 2020.”

“Cisco has determined that Cisco-maintained salt-master servers serving Cisco VIRL-PE versions 1.2 and 1.3 are at risk.”

Cisco

Six Cisco backend servers were compromised

As detailed by the company, hackers were able to compromise six backend infrastructure servers: us-1.virl.info, us-2.virl.info, us-3.virl.info, us-4.virl.info, vsm-us-1.virl.info, and vsm-us-2.virl.info.

The compromised servers were updated and remediated by Cisco on May 7, 2020, applying patches that address the authentication bypass vulnerability (CVE-2020-11651) and directory traversal vulnerability (CVE-2020-11652) affecting SaltStack servers.

Cisco also says that Cisco Modeling Labs Corporate Edition (CML) and Cisco Virtual Internet Routing Lab Personal Edition (VIRL-PE) products deployed in standalone or cluster configurations are also vulnerable to attacks because they “integrate a version of SaltStack that runs the salt-master service that is affected by these vulnerabilities.”

The company has released security updates that patch CML and VIRL-PE products and also provides a solution for customers who cannot immediately update their installations.

CML allows users to simulate Cisco and third-party devices, while VIRL-PE allows them to design and test virtual networks in development and test environments.

Attackers are actively exploiting SaltStack vulnerabilities

CVE-2020-11652 allows reading files outside the intended directory and, combined with CVE-2020-11651, gives unauthorized attackers full read and write access and allows them to steal the secret key required to authenticate to the salt-master server as root.

Cisco is not the first organization to announce a security breach caused by exploiting SaltStack vulnerabilities, with cybersecurity firm DigiCert, LineageOS, Vates, and blogging platform Ghost also reporting intrusions.

While most of the organizations that have been hacked in this way have stated that the ultimate goal of the attacks was to use the compromised servers for illegal currency mining, the possibility of other more insidious goals such as the development of more dangerous malicious payloads or the theft of sensitive information cannot be ruled out.

According to Censys as of May 1, there were more than 5,000 SaltStack servers exposed to the Internet.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS