Live data from Hacker News

Cisco Nexus 9000 Switches Allow SSH As Root

nvd.nist.gov

1–10 of 113 posts

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#3
This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice.

The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#4
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

You’re joking right?

It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#5
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root via IPv6 only.

Which makes it even more likely to be explained by stupidity as to malice.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#6
post #4
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

If mundanity is your concern, add an exclamation point to it.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#7
post #4
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

If it was a genuine "backdoor" why would you want use a publicly available key?

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#8
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

It allows anyone who knows the default SSH key pair to login as root. How is that not a backdoor?

Backdoor definition: "A backdoor is a method, often secret, of bypassing normal authentication in a computer system."

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#9
post #8
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

It allows anyone who knows the default SSH key pair to login as root. How is that not a backdoor? Backdoor definition: "A backdoor is a method, often secret, of bypassing normal authentication in a computer system."

People sometimes read "backdoor" as something intentionally left by an insider for later use by themselves or others.
Post reply on HN