Wednesday, March 28, 2018

Cisco Releases Security Updates

Original release date: March 28, 2018

Cisco has released updates to address vulnerabilities affecting multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

NCCIC/US-CERT encourages users and administrators to review the following Cisco Security Advisories and apply the necessary updates:


This product is provided subject to this Notification and this Privacy & Use policy.




from US-CERT National Cyber Alert System https://ift.tt/2GitbfS

Vulnerability Spotlight: Multiple Nvidia D3D10 Driver Pixel Shader Vulnerabilities

March 2018 Cisco IOS and IOS XE Software Bundled Publication


Today, we released the first Cisco IOS and IOS XE Software Security Advisory Bundled Publication of 2018. As a reminder, Cisco discloses vulnerabilities in Cisco IOS Software and Cisco IOS XE Software on a predictable schedule—the fourth Wednesday of March and September in each calendar year. Today’s release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication includes 20 advisories that disclose vulnerabilities in the following technologies and features:

  • Bidirectional Forwarding Detection (BFD)
  • Cisco Umbrella Integration
  • Command-line interface (CLI)
  • Dynamic Host Control Protocol (DHCP)
  • Integrated Services Module for VPN (ISM-VPN)
  • Internet Group Management Protocol (IGMP)
  • Internet Key Exchange (IKE)
  • Internet Protocol (IP)
  • Link Layer Discovery Protocol (LLDP)
  • Quality of Service (QoS)
  • Simple Network Management Protocol (SNMP)
  • Smart Install (SMI)
  • Web-based user interface (web UI)
  • Zone-Based Firewall (ZBF)

Make sure you take a look at the Cisco Event Response—our go-to document that correlates the full array of Cisco Security resources for this bundle, including links to the advisories, CVSS scores, and Security Impact Ratings. And don’t forget about the Cisco IOS Software Checker, the quickest way to determine your exposure to vulnerabilities disclosed in this advisory bundle and to identify the earliest release (“First Fixed Release”) that corrects all the vulnerabilities described in a particular security advisory. Cisco updates the Software Checker data daily to include the most current information. And, as you may recall from last year, the Software Checker now supports queries for Cisco IOS XE Software releases. You asked for this functionality and we listened.

As the project manager who oversees the management and delivery of these bundled disclosures, I have unique insight into the level of effort and collaboration involved—a dedicated team of incident managers, a variety of partner organizations, special tooling, months of preparation, and thousands of communications. All of these come together to deliver a bundled disclosure on the fourth Wednesday of March and September in each calendar year.

Cisco PSIRT is committed to improving our disclosure processes to meet your needs. We hope the publication timeline, enhanced tooling, and additional “bundling” help your organization plan and ensure that resources are available to analyze, test, and remediate these vulnerabilities in your environments. Please let us know in the comments below. We take your feedback seriously!

The next Cisco IOS and IOS XE Software Security Advisory Bundled Publication is scheduled for September 26, 2018. Mark your calendars now. And don’t forget—for all things security, visit the Cisco Security Portal, the primary outlet and home for Cisco security intelligence content.

Tags:



from Cisco Blog » Security https://ift.tt/2usZx1V

Cisco IOS and IOS XE Software Forwarding Information Base Denial of Service Vulnerability

This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS Software or Cisco IOS XE Software.

For information about which Cisco IOS and IOS XE Software releases are vulnerable, consult the Cisco bug ID(s) at the top of this advisory.

Determining the Cisco IOS Software Release

To determine which Cisco IOS Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and then refer to the system banner that appears. If the device is running Cisco IOS Software, the system banner displays text similar to Cisco Internetwork Operating System Software or Cisco IOS Software. The banner also displays the installed image name in parentheses, followed by the Cisco IOS Software release number and release name. Some Cisco devices do not support the show version command or may provide different output.

The following example shows the output of the command for a device that is running Cisco IOS Software Release 15.5(2)T1 and has an installed image name of C2951-UNIVERSALK9-M:

Router> show version

Cisco IOS Software, C2951 Software (C2951-UNIVERSALK9-M), Version 15.5(2)T1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2015 by Cisco Systems, Inc.
Compiled Mon 22-Jun-15 09:32 by prod_rel_team
.
.
.

For information about the naming and numbering conventions for Cisco IOS Software releases, see the Cisco IOS and NX-OS Software Reference Guide.

Determining the Cisco IOS XE Software Release

To determine which Cisco IOS XE Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and then refer to the system banner that appears. If the device is running Cisco IOS XE Software, the system banner displays Cisco IOS Software, Cisco IOS XE Software, or similar text.

The following example shows the output of the command for a device that is running Cisco IOS XE Software Release 16.2.1 and has an installed image name of CAT3K_CAA-UNIVERSALK9-M:

ios-xe-device# show version

Cisco IOS Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version Denali 16.2.1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Sun 27-Mar-16 21:47 by mcpre
.
.
.

For information about the naming and numbering conventions for Cisco IOS XE Software releases, see the Cisco IOS and NX-OS Software Reference Guide.

No other Cisco products are currently known to be affected by this vulnerability.

Cisco has confirmed that this vulnerability does not affect Cisco IOS XR Software or Cisco NX-OS Software.



from Cisco Security Advisory https://ift.tt/2pLMHqK

Cisco IOS XE Software Static Credential Vulnerability

Cisco has released free software updates that address the vulnerability described in this advisory. Customers may only install and expect support for software versions and feature sets for which they have purchased a license. By installing, downloading, accessing, or otherwise using such software upgrades, customers agree to follow the terms of the Cisco software license:
https://www.cisco.com/c/en/us/products/end-user-license-agreement.html

Additionally, customers may only download software for which they have a valid license, procured from Cisco directly, or through a Cisco authorized reseller or partner. In most cases this will be a maintenance upgrade to software that was previously purchased. Free security software updates do not entitle customers to a new software license, additional software feature sets, or major revision upgrades.

When considering software upgrades, customers are advised to regularly consult the advisories for Cisco products, which are available from the Cisco Security Advisories and Alerts page, to determine exposure and a complete upgrade solution.

In all cases, customers should ensure that the devices to be upgraded contain sufficient memory and confirm that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, customers are advised to contact the Cisco Technical Assistance Center (TAC) or their contracted maintenance providers.

Customers Without Service Contracts

Customers who purchase directly from Cisco but do not hold a Cisco service contract and customers who make purchases through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should obtain upgrades by contacting the Cisco TAC:
https://www.cisco.com/c/en/us/support/web/tsd-cisco-worldwide-contacts.html

Customers should have the product serial number available and be prepared to provide the URL of this advisory as evidence of entitlement to a free upgrade.

Cisco IOS and IOS XE Software

To help customers determine their exposure to vulnerabilities in Cisco IOS and IOS XE Software, Cisco provides a tool, the Cisco IOS Software Checker, that identifies any Cisco Security Advisories that impact a specific software release and the earliest release that fixes the vulnerabilities described in each advisory (“First Fixed”). If applicable, the tool also returns the earliest release that fixes all the vulnerabilities described in all the advisories identified (“Combined First Fixed”).

Customers can use this tool to perform the following tasks:

  • Initiate a search by choosing one or more releases from a drop-down list or uploading a file from a local system for the tool to parse
  • Enter the output of the show version command for the tool to parse
  • Create a custom search by including all previously published Cisco Security Advisories, a specific advisory, or all advisories in the most recent bundled publication

To determine whether a release is affected by any published Cisco Security Advisory, use the Cisco IOS Software Checker on Cisco.com or enter a Cisco IOS Software or Cisco IOS XE Software release—for example, 15.1(4)M2 or 3.13.8S—in the following field:



from Cisco Security Advisory https://ift.tt/2pOulV7

Cisco IOS XE Software Web UI Remote Access Privilege Escalation Vulnerability

This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled and authentication, authorization, and accounting (AAA) authorization is not configured for EXEC sessions. The default state of the HTTP Server feature is version-dependent.

This vulnerability was introduced in Cisco IOS XE Software Release 16.1.1. For more information about which Cisco IOS XE Software releases are vulnerable, see the Fixed Software section of this advisory.

Assessing the HTTP Server Configuration

To determine whether the HTTP Server feature is enabled for a device, administrators can log in to the device and use the show running-config | include http (secure|server) command in the CLI to check for the presence of the ip http server command or the ip http secure-server command in the global configuration. If either command is present and configured, the HTTP Server feature is enabled for the device.

The following example shows the output of the show running-config | include http (secure|server) command for a router that has the HTTP Server feature enabled:

Router# show running-config | include http (secure|server)

ip http server
ip http secure-server

Assessing the AAA Configuration

To determine whether AAA authorization for EXEC sessions is configured for a device, administrators can log in to the device and use the show running-config | include aaa authorization exec command in the CLI to check for the presence of the aaa authorization exec [options] command in the global configuration.

The following example shows the output of the show running-config | include aaa authorization exec command for a router that is configured to have its AAA authorization enforced by a TACACS+ server and is therefore not affected by this vulnerability:

Router# show running-config | include aaa authorization exec

aaa authorization exec use-tacacs group tacacs+

Determining the Cisco IOS XE Software Release

To determine which Cisco IOS XE Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and then refer to the system banner that appears. If the device is running Cisco IOS XE Software, the system banner displays Cisco IOS Software, Cisco IOS XE Software, or similar text.

The following example shows the output of the command for a device that is running Cisco IOS XE Software Release 16.2.1 and has an installed image name of CAT3K_CAA-UNIVERSALK9-M:

ios-xe-device# show version

Cisco IOS Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version Denali 16.2.1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Sun 27-Mar-16 21:47 by mcpre
.
.
.

For information about the naming and numbering conventions for Cisco IOS XE Software releases, see the Cisco IOS and NX-OS Software Reference Guide.

No other Cisco products are currently known to be affected by this vulnerability.

Cisco has confirmed that this vulnerability does not affect Cisco IOS Software, Cisco IOS XR Software, or Cisco NX-OS Software.



from Cisco Security Advisory https://ift.tt/2pM3JoF

Cisco IOS XE Software Arbitrary File Write Vulnerability

This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled. The default state of the HTTP Server feature is version-dependent.

For information about which Cisco IOS XE Software releases are vulnerable, consult the Cisco bug ID(s) at the top of this advisory.

Assessing the HTTP Server Configuration

To determine whether the HTTP Server feature is enabled for a device, administrators can log in to the device and use the show running-config | include http (secure|server) command in the CLI to check for the presence of the ip http server command or the ip http secure-server command in the global configuration. If either command is present and configured, the HTTP Server feature is enabled for the device.

The following example shows the output of the show running-config | include http (secure|server) command for a router that has the HTTP Server feature enabled:

Router# show running-config | include http (secure|server)

ip http server
ip http secure-server

Determining the Cisco IOS XE Software Release

To determine which Cisco IOS XE Software release is running on a device, administrators can log in to the device, use the show version command in the CLI, and then refer to the system banner that appears. If the device is running Cisco IOS XE Software, the system banner displays Cisco IOS Software, Cisco IOS XE Software, or similar text.

The following example shows the output of the command for a device that is running Cisco IOS XE Software Release 16.2.1 and has an installed image name of CAT3K_CAA-UNIVERSALK9-M:

ios-xe-device# show version

Cisco IOS Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version Denali 16.2.1, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Sun 27-Mar-16 21:47 by mcpre
.
.
.

For information about the naming and numbering conventions for Cisco IOS XE Software releases, see the Cisco IOS and NX-OS Software Reference Guide.

No other Cisco products are currently known to be affected by this vulnerability.

Cisco has confirmed that this vulnerability does not affect Cisco IOS Software, Cisco IOS XR Software, or Cisco NX-OS Software.



from Cisco Security Advisory https://ift.tt/2pRDFb5