Live data from Hacker News

Cisco Nexus 9000 Switches Allow SSH As Root

nvd.nist.gov

61–70 of 113 posts

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#61
This is a nasty one! Sloppy in hindsight.

There is one bright side to otherwise disgraceful incidents: All the customers running older versions are now forced to upgrade to the latest versions. The burden of supporting really old versions suddenly vanishes.

Box vendors should really stop selling unmanaged boxes/solutions. In reality, customers end up buying service contracts anyway along with boxes. Instead, sell usage/service/connectivity and manage the hardware. A critical patch like this one could then be applied before a PSIRT is released. Frequent upgrades(security patches or feature/bug fix patches) are now commonplace. The user experience would be so much better if the solution were managed by the vendor (cloud managed).

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#62
post #40

If a compamy as big as Cisco can screw this kind of thing so badly, the future of IoT looks bleak.

in most offices i can just wait around until the cleaning lady comes, pretend to forget something, go in and loot anything I want.

most people don't care about security until they get looted

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#63
post #56
post #48

I surely can't be the only one who sees open down to the hardware replacements as the only solution to this type of problems.

For most enterprise IT products there is no "open down to the hardware" replacement and there never will be because there isn't a business model to create it.

The Facebook open compute network gear is, and is equivalent to the Cisco Nexus series

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#64

Earlier quoted context omitted.

>But any competently inserted intentional backdoor is going to be indistinguishable from a mistake. Maybe, but without proof it's still just speculation. Real bugs do occur often, and sometimes in sensitive areas. I understand wanting to be vigilant. In both assuming malice and assuming human error though, you're still forced to make an assumption.

You're not forced to make an assumption, you can just be honest and say you don't know. There's too many comments in this thread effectively saying "it looks unintentional, so it's unintentional".

>You're not forced to make an assumption, you can just be honest and say you don't know.

Indeed. That's what I was trying to say.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#65

can someone help me understand this better.. Did Cisco leave a user public key in the switch and the private key has leaked ? To exploit this vulnerability attacker has to get hold of that private key ?

The keypair is essentially some default known value. You shouldn't be able to use this to connect at all, but apparently works over IPv6. So you'd have to have the private key, as well as knowing the IPv6 address of the device you're connecting to, and that device would have to have a route to the internet or a location you could connect to it from.

Any idea why it works for v6 but not v4 ? SSH authentication itself is agnostic to the IP version, no ?

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#66
post #48

I surely can't be the only one who sees open down to the hardware replacements as the only solution to this type of problems.

As a former Cisco employee, I can tell you why companies never want to open source their security-sensitive products:

Pros of open sourcing a product:

- fewer total number of vulnerabilities

Cons of open sourcing a product:

- more publicly-known vulnerabilities

- less effort required to find new vulnerabilities

The product might be more objectively secure, with more bug reports and more fixes.

But it will be less practically secure. There will be more known vulnerabilities, and many customers can't upgrade, leaving more total vulnerable customers. And worse, now anyone on the internet can try and find new vulnerabilities for $0, while before they'd need to buy a $1,000+ piece of hardware to even get a shot at the compiled code.

The real defense against this problem is security auditing. Security engineers try to hack the device while asking a bunch of questions about SSH connections and private keys. This is the technique most companies employ, often combined with bug bounties.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#67
post #45

Earlier quoted context omitted.

Cisco hasn't had a good reputation for awhile IMO.

Like any other network solutions vendor?

I heard https://nvd.nist.gov/vuln/detail/CVE-2019-1804 is Cisco's ninth backdoor so far this year. Not ninth security problem total, ninth backdoor. The ninth security problem Cisco shipped intentionally.

Meanwhile, the router that serves my office is from a company that's had fewer than nine security problems in the past ten years. Two, I think, but I confess I don't really keep count (ditto the nine above). The precise number doesn't matter, because

1. If you want to be cynic you can point out that 9>0 and 2>0 and really they all suck.

2. And if you don't want to be cynic, then Cisco's recent record is in a league of its own. Steals the show. Makes other people's CVE count look like rounding errors.

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#69
post #67
post #45

Earlier quoted context omitted.

Like any other network solutions vendor?

I heard https://nvd.nist.gov/vuln/detail/CVE-2019-1804 is Cisco's ninth backdoor so far this year. Not ninth security problem total, ninth backdoor. The ninth security problem Cisco shipped intentionally . Meanwhile, the router that serves my office is from a company that's had fewer than nine security problems in the past ten years. Two, I think, but I confess I don't really keep count (ditto the nine above). The pr…

Can you tell us your vendor?

We are moving offices, and it's time to change equipment, Been reading about but still haven't gotten a good list.

The only thing i found is great micro tick for wifi routing/AP's

Re: Cisco Nexus 9000 Switches Allow SSH As Root

#70

Earlier quoted context omitted.

HackerNews: Huueerrggg Huawei can't even write secure code Cisco: Hold my beer

The Huawei stuff is pretty bad, but the comments read like they've been copied pasted each time here. It's the exact same talking points.

Because the anti Huawei talk is obviously not in people's interest. Just look how zero politicians worldwide lament that Cisco should be banned from anything related to internet infrastructure despite showing again and again that they are unwilling to stop implementing backdoors. Cisco makes it obvious that backdoors are A OK as long as it's our backdoors. No one acting against Huawei actually cares about peoples security.
Post reply on HN