bk99.de entertain the web since 1997

Cisco warns of security holes it will not patch

Summary

In January 2023 Cisco warned of critical holes in the small business routers RV016, RV042, RV042G and RV082, but announced that it would not deliver any more updates. Manipulated HTTP requests to the web interface could bypass authentication and gain root access (CVE-2023-20025). As the devices had reached end of life, Cisco only pointed to blocking ports 443 and 60443, although proof-of-concept code already existed.

Ideas

  • Devices past end of support remain permanently vulnerable.
  • A second hole (CVE-2023-20026) allowed code execution with admin credentials.
  • Without a reachable management interface, neither hole can be exploited.
  • At Cisco, hardware support and software maintenance end at different times.

Insights

  • A device’s end of support is a security date, not just a contract date.
  • Workarounds do not replace patches when attack code is already circulating.

Facts

  • Support for the RV082 and RV016 ended in 2021.
  • Software maintenance for the RV042 and RV042G ended in 2021; the hardware was supported until 2025.

References

Critique

  • The report does not say how many of these routers were still reachable from the internet.

Recommendations

  • Keep an inventory with end-of-support dates for all network devices.
  • Replace routers before their software maintenance ends, not only after a hole.

Read the original article

Search the Web Archive