Live data from Hacker News

Cisco Nexus 9000 Switches Allow SSH As Root

nvd.nist.gov

11–20 of 113 posts

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#11
post #7
post #4

Earlier quoted context omitted.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

If it was a genuine "backdoor" why would you want use a publicly available key?

This isn't a backdoor but it is a major vulnerability.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#12
post #6
post #4

Earlier quoted context omitted.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

If mundanity is your concern, add an exclamation point to it.

Accuracy helps.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#13
post #4
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

Sad state of affairs when terrible, ugly vulnerabilities are mundane.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#14
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

It is impossible to know the motivation of the person who put this here but these constructs have no place in firmware for critical devices and Cisco should have known that for a long time already. Either they truly are idiots or this is malicious.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#15
post #7
post #4

Earlier quoted context omitted.

You’re joking right? It’s “allow ssh as root with a publicly available ssh key”. Your version is making it sound mundane.

If it was a genuine "backdoor" why would you want use a publicly available key?

Being the only keyholder reduces plausable deniability, so maybe.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#16
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

this headline is outrages! only china would ever place backdoors into critical infrastructure equipment, the US free market would never do such a thing!

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#17
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

The mods asked me to email comments like this to the hn@yc.c address in the footer (Contact link), and have been responsive (not necessarily agreed, but they do reply!) when I've done so. I emailed them a link to your comment as the edit request with an attempt of my own:

> CVS-2019-1804: Cisco Nexus 9000 remote root exploit via SSH-over-IPv6

(Yes, it's a backdoor, I ran out of time sorry)

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#18
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

And plausible deniability is the #1 rule when being malicious. If you know enough to use an asymmetric key instead of a password, but not enough to think it's a good idea to leave the private key there, you're in a weird cross-section of expertise.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#19
post #3

This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.

What is a backdoor if not this?

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#20
post #7

Earlier quoted context omitted.

If it was a genuine "backdoor" why would you want use a publicly available key?

Being the only keyholder reduces plausable deniability, so maybe.

The private key is on the shipped devices, from my reading.
Post reply on HN