News

Vulnerability in Cisco IOS XE allows invasion in internal networks through a malicious link

Cisco fixed a dangerous vulnerability in user’s interface of its IOS XE product that allows outsiders penetrating internal networks without authorization.

Cross-Site Request Forgery (CSRF) vulnerability has been identified with CVE-2019-1904.

Cisco IOS XE is a Linux kernel-based network operating system used on various enterprise-level routers and Cisco Catalyst switches. Versions of IOS, IOS XR and NX-OS are not affected.

“This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software with the HTTP Server feature enabled”, — inform in Cisco.

The cause of the problem is in insufficient protection of web-interface from CSRF.

Attacker could use it by forcing user to follow malicious link (for example, an exploit can be hidden in a malicious ad).

Read also: Cisco fixed dangerous vulnerabilities in its industrial and enterprise solutions

Since vulnerability can be exploited completely unnoticed, it is a very attractive tool for cybercriminals.

Successful exploitation of the vulnerability allows an attacker to perform any actions with the same rights that has the attacked user.

“If the user has administrator rights, an attacker can change the configuration, execute commands, or reboot the affected device”, – explained Cisco experts.

The only way to fix this vulnerability is to install the latest updates (only available to users with a valid license).

A PoC-exploit for vulnerability already exists, but no evidence of its exploitation in real attacks was found.

Source: https://tools.cisco.com

User Review
0 (0 votes)
Comments Rating 0 (0 reviews)
Daniel Zimmermann

Daniel Zimmermann has been writing on security and malware subjects for many years and has been working in the security industry for over 10 years. Daniel was educated at the Saarland University in Saarbrücken, Germany and currently lives in New York.

Recent Posts

Remove Colidunt.xyz pop-up ads (Virus Removal Guide)

Colidunt.xyz is a domain that tries to trick you into clik to its browser notifications…

12 hours ago

Remove Myflisblog pop-up ads (Virus Removal Guide)

Myflisblog.com is a site that tries to trick you into subscribing to its browser notifications…

12 hours ago

Remove Dofenpas.xyz pop-up ads (Virus Removal Guide)

Dofenpas.xyz is a domain that tries to trick you into subscribing to its browser notifications…

12 hours ago

Remove Bifotend.xyz pop-up ads (Virus Removal Guide)

Bifotend.xyz is a site that tries to trick you into subscribing to its browser notifications…

12 hours ago

Remove Likudservices pop-up ads (Virus Removal Guide)

Likudservices.com is a domain that tries to trick you into clik to its browser notifications…

3 days ago

Remove Codebenmike.live pop-up ads (Virus Removal Guide)

Codebenmike.live is a site that tries to trick you into subscribing to its browser notifications…

3 days ago