HomeInvestigationsCisco Smart Install: Makes thousands of web devices vulnerable worldwide

Cisco Smart Install: Makes Thousands of Web Devices Vulnerable Worldwide

Security researcher Dimitris Roussis analyzes how a single incorrect setting in the Smart Install feature provided by Cisco devices makes thousands of web devices vulnerable worldwide.

Smart Install enables a networked device that is integrated into a corporate network to automatically configure itself without the intervention of a network administrator. Currently, thousands of active Cisco devices are configured to provide the Smart Install feature accessible from the internet.

See Also: Identity Theft Scams – What is it and how to protect yourself?

Cisco Smart Install: Makes Thousands of Network Devices Vulnerable Worldwide
Cisco Smart Install web devices vulnerability

An attacker can exploit this setting and gain access to web devices with the ability to remotely execute any command, such as disabling the network device, making the corporate network inaccessible to the entire Organization/Company, intercepting or changing passwords, etc.

The above is presented in the analysis that the researcher provides below.

See Also: Malicious KMSpico installers are used to steal crypto wallets

Initially, as part of the research, a random sample of 100 web devices, among thousands, is searched for through the Shodan search engine.

An automated script is then used to check which of the random sample network devices are vulnerable. The script also uses code that is publicly available on the internet.

The final result of the script is the creation of a file (vulnerable_devices.txt) that includes the IPs of the vulnerable network devices.

See Also: Thieves are using AirTags to steal your car

Cisco Smart Install: Makes Thousands of Web Devices Vulnerable Worldwide

Additionally, to demonstrate the severity of the vulnerability, the script connects to the network device and downloads its entire config file to the local tftp folder.

Cisco Smart Install: Makes Thousands of Web Devices Vulnerable Worldwide

Corresponding to the download of the config file through this vulnerability, any command can be executed on the network device.

It is worth noting that among the affected network devices, several are also located in Greece, as evidenced by the Shodan search engine.

See Also: Phishing campaign uses fake Office 365 notifications to stealcredentials

Cisco Smart Install: Makes Thousands of Web Devices Vulnerable Worldwide

To prevent the attack from being possible, Network Administrators must immediately disable the Smart Install feature if it is not being used or restrict access to it through ACL rules that will not allow access to port 4786 from the Public network (Internet).

Cisco Smart Install: Makes Thousands of Web Devices Vulnerable Worldwide

Technical analysis by Dimitris Roussis: Dimitris Roussis is a member of the Information Systems Security Laboratory of the University of the Aegean.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS