Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Cisco IOS XE routers Software Authentication Bypass Vulnerability

3 Weeks Ago   #1
Brink

64-bit Windows 10 Pro
 
 
Cisco IOS XE routers Software Authentication Bypass Vulnerability

Quote:
Summary

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device.

The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploit this vulnerability by submitting malicious HTTP requests to the targeted device. A successful exploit could allow the attacker to obtain the token-idof an authenticated user. This token-id could be used to bypass authentication and execute privileged actions through the interface of the REST API virtual service container on the affected Cisco IOS XE device.

The REST API interface is not enabled by default and must be installed and activated separately on IOS XE devices. See the Details section for more information.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability

Affected Products

This vulnerability affects Cisco devices that are configured to use a vulnerable version of Cisco REST API virtual service container. At the time of publication, this vulnerability affected the following products:
  • Cisco 4000 Series Integrated Services Routers
  • Cisco ASR 1000 Series Aggregation Services Routers
  • Cisco Cloud Services Router 1000V Series
  • Cisco Integrated Services Virtual Router
Vulnerable Products

This vulnerability resides in the Cisco REST API virtual service container; however, it affects devices running Cisco IOS XE Software when exploited. If a vulnerable release of the Cisco REST API virtual service container is enabled, the underlying Cisco IOS XE device is affected.

This vulnerability affects Cisco devices when all of the following conditions are met:
  • The device runs an affected Cisco IOS XE Software release.
  • The device has an installed and enabled affected version of the Cisco REST API virtual service container.
Cisco has released a fixed version of the REST API virtual service container. Cisco has also released a hardened Cisco IOS XE Software release that prevents installation or activation of a vulnerable container on a device. If the device was already configured with an active vulnerable container, the IOS XE Software upgrade will deactivate the container, making the device not vulnerable. In that case, to restore the REST API functionality, customers should upgrade the Cisco REST API virtual service container to a fixed software release.


Read more: Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability


My System SpecsSystem Spec
.
Reply

 Cisco IOS XE routers Software Authentication Bypass Vulnerability




Thread Tools




Similar help and support threads
Thread Forum
Cisco warns over critical ASR 9000 Series router vulnerability
Source: Cisco IOS XR 64-Bit Software for Cisco ASR 9000 Series Aggregation Services Routers Network Isolation Vulnerability See also: Cisco warns over critical router flaw | ZDNet
News
Hackers started attacks on Cisco RV110W, RV130W, and RV215W routers
Read more: Hackers have started attacks on Cisco RV110, RV130, and RV215 routers | ZDNet See also: Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
News
Need help with share authentication
I have a computer running Win7 Pro and I'm trying to set up a home network with it. I have a USB external hard drive plugged into it that I've networked. I'm trying to set it up so everyone in the house has their own login and can't view each other's stuff. I tried making a local account for my...
Network & Sharing
Authentication Help
EDIT: I meant Activation, not authentication! :o I bought the student upgrade version of 7 a while back without realizing that it was simply an upgrade meant to be applied to a computer with an earlier version of Windows already installed. I didn't notice this until I went to use the...
Installation & Setup
Wireless Authentication?
I am trying to access my wireless network at home and receive the following window when Win 7 finds my network. NETWORK AUTHENTICATION I receive a login box. What is it looking for? Router name and password? Windows login Info? Is this something Microsoft fixed in a latest update? I have not...
Network & Sharing


Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 13:46.
Twitter Facebook