Advertisement






Cisco Umbrella Virtual Appliance 2.1.0 Hardcoded Credentials

CVE Category Price Severity
CVE-2017-12350 CWE-798 Not specified High
Author Risk Exploitation Type Date
Rahul Pratap Singh High Remote 2017-11-17
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:OF/RC:C 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017110108

Below is a copy:

Cisco Umbrella Virtual Appliance 2.1.0 Hardcoded Credentials
Cisco Umbrella Virtual Appliance - Hardcoded Credentials (CVE-2017-12350)

Overview

"As the industryas first Secure Internet Gateway in the cloud, Cisco Umbrella provides the first line of defense against threats on the internet. Because Umbrella is delivered from the cloud, it is the easiest way to protect all of your users in minutes."

(https://umbrella.cisco.com/)

Issue

The Cisco Umbrella virtual appliance (version 2.1.0 and below) contains undocumented hardcoded credentials which could allow an attacker able to access the hypervisor console, persistent and unrestricted access to the virtual appliance.

Impact

An attacker able to access the hypervisor console could use the hardcoded credentials on the virtual appliance, elevate their privileges to root from a trusted system user and perform a wide range of attacks.

Timeline

October 10, 2017 - Notified Cisco via [email protected]
October 11, 2017 - Cisco assigned a case number
November 8, 2017 - Cisco advised that the issue has been resolved and that a security advisory will be published on November 15, 2017
November 15, 2017 - Cisco published a security advisory to document this issue

Solution

Upgrade to virtual appliance 2.1.2 or later

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171115-uva

CVE-ID: 

CVE-2017-12350

Questions?

https://www.info-sec.ca/contact.html

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum