If you have the Cisco 9000 Series, patch them now! This SSH backdoor allows an unauthenticated, remote attacker to login as root.
Cisco Nexus 9000 Switches Allow SSH As Root
31–40 of 113 posts
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#32Re: Cisco Nexus 9000 Switches Allow SSH As Root
#33This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
Submitted title was "Backdoor Found in Cisco Routers CVE-2019-1804".
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#34Western governments: Huawei needs to be banned from our collective infrastructure because backdoors Also western governments: Cisco will remedy their errors
Cisco: Hold my beer
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#35This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#36If you have the Cisco 9000 Series, patch them now! This SSH backdoor allows an unauthenticated, remote attacker to login as root.
Cisco model numbers are fun.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#37Western governments: Huawei needs to be banned from our collective infrastructure because backdoors Also western governments: Cisco will remedy their errors
HackerNews: Huueerrggg Huawei can't even write secure code Cisco: Hold my beer
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#38This is a pretty egregiously editorialized title; what we know is that there's apparently an SSH keypair authorized on these devices, for which the private key is available on the device. That's a terrible, ugly vulnerability, but it's as likely due to stupidity as to malice. The right title is something like: CVS-2019-1804: Cisco Nexus 9000 Switches Allow SSH As Root.
It is impossible to know the motivation of the person who put this here but these constructs have no place in firmware for critical devices and Cisco should have known that for a long time already. Either they truly are idiots or this is malicious.
Re: Cisco Nexus 9000 Switches Allow SSH As Root
#39Earlier quoted context omitted.
What is a backdoor if not this?
A backdoor to me suggests an intentional loophole through a level of security. A bug that does the same is severe, but isn't intentional. At least that's my reading.
If Cisco had some SecretFBIChinaBackdoor() function somewhere the backlash would be way way worse (or at least an unknown). Whereas at this point it's abundantly clear that serious "non intentional" security vulnerabilities in networking hardware basically go ignored by the market.