8 ms·
Cisco Nexus 9000 Switches Allow SSH As Root
- sky_nox 7y agoIf you have the Cisco 9000 Series, patch them now! This SSH backdoor allows an unauthenticated, remote attacker to login as root.
- keanebean86 7y agoThis is exactly why I only buy belkin routers. I can't even connect to it.
- phs318u 7y agoHa! Thanks for making me laugh out loud.
- jauer 7y agoNexus 9000, running ACI, not normal NX-OS, as opposed to the ASR 9000 series which are common internet routers. Cisco model numbers are fun.
- broknbottle 7y agogod I still have nightmares about cisco sales rep trying to push ACI as the "solution to all problems".
- walrus01 7y agoAlso you should have ACLs in place and VLAN segmentation (assuming their use as pure layer 2 devices) so that only certain authorized sections of the network are even able to reach things like the management ssh and SNMP daemons.
- C1sc0cat 7y agoOr turn that all that shit off and go full Out of Band management - ok there are some trade-offs here.
- rakkhi 7y agoWithout wanting to start a political flame war it would be great if there was consistency to how we in the tech community and the media treat these types of vulnerabilities. When Huawei have these sorts of bugs they are reported as backdoors. Bugs happen in software be nice if put the nationalism aside and reported it consistently as bugs or vulnerabilities
- mobilemidget 7y ago'unauthenticated' should have been in the title of this post
- dagw 7y agoGiven that it is a $30k+ piece of kit I suspect not too many people here have them.
- tptacek 7y agoThis is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
- RL_Quine 7y agoYou’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.
- tptacek 7y agoIf mundanity is your concern, add an exclamation point to it.
- RL_Quine 7y agoAccuracy helps.
- fungi 7y agoIf it was a genuine "backdoor" why would you want use a publicly available key?
- anxman 7y agoThis isn't a backdoor but it is a major vulnerability.
- MaulingMonkey 7y agoBeing the only keyholder reduces plausable deniability, so maybe.
- RL_Quine 7y agoThe private key is on the shipped devices, from my reading.
- mkj 7y agoIs there an explanation of why it's ipv6 only?
- wmf 7y agoACI control traffic is probably IPv6-only. They may be taking advantage of link-local addressing.
- pmc 7y agoAn increased use of SSH keys for credential guessing is also found in our SSH honeypot: https://pmcao.github.io/caudit/ https://pmcao.github.io/caudit/
- e12e 7y agoHeh - people are harvesting compromised secret keys then? Because "guessing" secret keys shouldn't be viable?
- GalacticDomin8r 7y agoHuawei you all feel about that now? This is a true backdoor, not some silly telnet left on.
- alfiedotwtf 7y agoWestern governments: Huawei needs to be banned from our collective infrastructure because backdoors Also western governments: Cisco will remedy their errors
- King-Aaron 7y agoHackerNews: Huueerrggg Huawei can't even write secure code Cisco: Hold my beer
- ShorsHammer 7y agoThe Huawei stuff is pretty bad, but the comments read like they've been copied pasted each time here. It's the exact same talking points.
- bildung 7y agoBecause the anti Huawei talk is obviously not in people's interest. Just look how zero politicians worldwide lament that Cisco should be banned from anything related to internet infrastructure despite showing again and again that they are unwilling to stop implementing backdoors. Cisco makes it obvious that backdoors are A OK as long as it's our backdoors. No one acting against Huawei actually cares about peoples security.
- alfiedotwtf 7y agoIs it xenophobia masquerading as national security, or national security masquerading as xenophobia? Neither... it's nothing but hegemony with the pretext of both.
- m-p-3 7y agoIf a compamy as big as Cisco can screw this kind of thing so badly, the future of IoT looks bleak.
- threatofrain 7y agoCisco hasn't had a good reputation for awhile IMO.
- snaky 7y agoLike any other network solutions vendor?
- Arnt 7y agoI heard https://nvd.nist.gov/vuln/detail/CVE-2019-1804 https://nvd.nist.gov/vuln/detail/CVE-2019-1804 is Cisco's ninth backdoor so far this year. Not ninth security problem total, ninth backdoor. The ninth security problem Cisco shipped intentionally. Meanwhile, the router that serves my office is from a company that's had fewer than nine security problems in the past ten years. Two, I think, but I confess I don't really keep count (ditto the nine above). The precise number doesn't matter, because 1. If you want to be cynic you can point out that 9>0 and 2>0 and really they all suck. 2. And if you don't want to be cynic, then Cisco's recent record is in a league of its own. Steals the show. Makes other people's CVE count look like rounding errors.
- unionpivo 7y agoCan you tell us your vendor? We are moving offices, and it's time to change equipment, Been reading about but still haven't gotten a good list. The only thing i found is great micro tick for wifi routing/AP's
- Arnt 7y agoMikrotik is okay for small routers, and so is Ubiquiti. If you get Mikrotiks, look for ones with angly metal boxes, not curvy plastic ones. And avoid the GUI stuff, use the CLI. If you're looking for larger routers I'd look at Juniper first. All of those will give you hardware that does the job and stays up, and provide uncomplicated upgrades for many years.
- ggm 7y agoBut Huawei...
- userbinator 7y agoI don't own nor have I read the manual of one of these, and there's not much in the way of details on that page, but isn't this more like "use the factory-supplied default key to get in for the first time, then change it to your own"?
- wmf 7y agoPeople are calling it a backdoor because presumably it was not documented anywhere.
- fulafel 7y agoWhat product segment is this, what kind of organizations are likely have them? Also, link to Cisco's own advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey https://tools.cisco.com/security/center/content/CiscoSecurit...
- wmf 7y agoIt's a switch used in enterprise data centers. It's pretty critical because servers plug directly into it.
- madez 7y agoI surely can't be the only one who sees open down to the hardware replacements as the only solution to this type of problems.
- wmf 7y agoFor most enterprise IT products there is no "open down to the hardware" replacement and there never will be because there isn't a business model to create it.
- travbrack 7y agoThe Facebook open compute network gear is, and is equivalent to the Cisco Nexus series
- bmalehorn 7y agoAs a former Cisco employee, I can tell you why companies never want to open source their security-sensitive products: Pros of open sourcing a product: - fewer total number of vulnerabilities Cons of open sourcing a product: - more publicly-known vulnerabilities - less effort required to find new vulnerabilities The product might be more objectively secure, with more bug reports and more fixes. But it will be less practically secure. There will be more known vulnerabilities, and many customers can't upgrade, leaving more total vulnerable customers. And worse, now anyone on the internet can try and find new vulnerabilities for $0, while before they'd need to buy a $1,000+ piece of hardware to even get a shot at the compiled code. The real defense against this problem is security auditing. Security engineers try to hack the device while asking a bunch of questions about SSH connections and private keys. This is the technique most companies employ, often combined with bug bounties.
- thickice 7y agocan someone help me understand this better.. Did Cisco leave a user public key in the switch and the private key has leaked ? To exploit this vulnerability attacker has to get hold of that private key ?
- rando444 7y agoThe keypair is essentially some default known value. You shouldn't be able to use this to connect at all, but apparently works over IPv6. So you'd have to have the private key, as well as knowing the IPv6 address of the device you're connecting to, and that device would have to have a route to the internet or a location you could connect to it from.
- thickice 7y agoAny idea why it works for v6 but not v4 ? SSH authentication itself is agnostic to the IP version, no ?
- mckenna 7y agoThis is a nasty one! Sloppy in hindsight. There is one bright side to otherwise disgraceful incidents: All the customers running older versions are now forced to upgrade to the latest versions. The burden of supporting really old versions suddenly vanishes. Box vendors should really stop selling unmanaged boxes/solutions. In reality, customers end up buying service contracts anyway along with boxes. Instead, sell usage/service/connectivity and manage the hardware. A critical patch like this one could then be applied before a PSIRT is released. Frequent upgrades(security patches or feature/bug fix patches) are now commonplace. The user experience would be so much better if the solution were managed by the vendor (cloud managed).
- legooolas 7y agoMost places (especially where they have enough money to be buying Cisco Nexus 9k kit) will want some sort of change management, not the vendor to be making arbitrary changes to their critical infrastructure. Also, given the number and severity of these sort of vulnerabilities in recent times, do you want to give the same companies remote access to your infrastructure as well? :)
- Hikikomori 7y agoCisco bought meraki that provides a cloud managed solution, but it's only office equipment.
- pjc50 7y ago> Box vendors should really stop selling unmanaged boxes/solutions Users should no longer be allowed to own their own hardware? That'll be popular with both the hacker crowd and the high-security people. What of devices that are never intended to be connected to the wider internet?
- jeffrallen 7y agoDude, Cisco, you had one job.
- bildung 7y agoAnd they completed it successfully. They literally had a new backdoor every month for years now. No company is that incompetent unless ordered to be so.
- crispyambulance 7y ago> Cisco Nexus 9000 Switches Allow SSH As Root Cisco Nexus 9000 Switches [have a vulnerability that Allows an attacker to] SSH As Root [over IPV6 using a default key-pair]
- samat 7y agoAre this devices normally left with accessible 22 port in the wild?
- voidmain0001 7y agoA Nexus 9K is an expensive piece of kit, and is not a trivial switch to deploy what with VPC and other configurations being commonplace, so just powering it on will not deliver a workable product. I suspect most if not all deployments follow best practice and have a management VLAN with access lists control limiting the source address of the connecting client, and blocking access to port 22 from other networks. * Edit * Plus the Nexus the backdoor is only relevant if the switch in using ACI, and not standalone NX-OS mode. ACI training is a 5 day course for advanced engineers. https://www.cisco.com/c/en/us/training-events/training-certifications/training/training-services/courses/configuring-cisco-nexus-9000-series-switches-in-aci-mode-dcac9k.html https://www.cisco.com/c/en/us/training-events/training-certi...
- kuon 7y agoI worked with Cisco a lot in the past. I am so happy we have more and more open source alternative to replace all those network solution vendors.