Security holes: patches protect Cisco firewalls and switches
Summary
In August 2023 Cisco closed several holes in firewalls and switches. Rated high were an SNMP hole in Firepower 4100 and 9300 through which authenticated attackers could trigger restarts, an IS-IS hole in Nexus 3000 and 9000 without authentication, and a DoS hole in NX-OS. Further medium holes affected, among others, the Application Policy Infrastructure Controller.
Ideas
- Management protocols such as SNMP are a risk to availability even after authentication.
- Prepared routing protocol packets can bring down switches.
- Authentication services such as TACACS+ and RADIUS were also an attack path.
Insights
- Denial of service on core network components hits all connected services.
- Routing and management protocols belong on separate, trusted network segments.
Facts
- The SNMP hole is listed as CVE-2023-20200.
- The IS-IS hole CVE-2023-20169 could be exploited without authentication.
References
Critique
- The report is a list of advisories without classifying how exposed the protocols typically are.
Recommendations
- Restrict SNMP to a management network and use SNMPv3 with authentication.
- Only accept IS-IS and other routing messages from known neighbours.
Links to the original source and the Web Archive open in a new tab.