HomeSecurityCisco will not fix vulnerability found in EoL routers

Cisco will not fix vulnerability found in EoL routers

Cisco says there is a new vulnerability that allows authentication bypass and affects many small business VPN routers However, . the company said that it will not release a patch to fix this vulnerability because the affected devices have reached their end of life (EoL). This means that Cisco no longer supports them and does not offer security updates, etc.

Cisco router vulnerability

The vulnerability (CVE-2022-20923) is a zero-day bug caused by a flawed password validation algorithm, which could be exploited by malicious users to connect to the VPN on vulnerable devicesusing what the company describes as “crafted credentials.” This can be done if the IPSec VPN Server feature is enabled.

See also: HP: Fixes bug in pre-installed Support Assistant tool

"A successful exploit could allow an attacker to bypass authentication and gain access to the IPSec VPN network," Cisco explained in a security advisory it published.

“The attacker can gain privileges at the same level as an administrator, depending on the crafted credentials used“.

To see if IPSec VPN Server is enabled on a router, you need to log in to the web-based management interface and go to VPN > IPSec VPN Server > Setup.

If the “ Server Enable ” checkbox is selected , the device is exposed to attempts to exploit CVE-2022-20923.

Cisco says its researchers have found no evidence that the vulnerability by cybercriminals.

See also: North Face: 200,000 accounts compromised through credential stuffing

Cisco will not fix vulnerability found in EoL routers
Cisco will not fix vulnerability found in EoL routers

Cisco: If you want to stay safe, choose newer router models

Cisco has asked customers still using the RV110W, RV130, RV130W and RV215W routers, which are affected by this vulnerability, to upgrade to newer models that still receive security updates.

According to Cisco, the vulnerable routers were available for order until December 2, 2019.

" Cisco has not released and will not release updates to address the vulnerability described in this advisory software ," the company added

“Customers are encouraged to upgrade to Cisco Small Business RV132W, RV160, or RV160W Routers“.

See also: Samsung on latest data breach: What information was stolen

It's worth noting that the CVE-2022-20923 vulnerability is not the first serious vulnerability affecting these EoL router models. In August 2021, the company said it did not plan to release updates for a critical vulnerability (CVE-2021-34730) that allowed unauthenticated users to remotely execute code as the root user. And at that time, the company had asked users to upgrade to newer models to stay safe.

In June of this year, Cisco again advised owners to upgrade to newer router models after the disclosure of a new critical vulnerability (CVE-2022-20825), which was also not patched due to the vulnerable devices being no longer supported.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS