Cisco buffer overflow vulnerability with remote code execution
1–10 of 23 posts
Re: Cisco buffer overflow vulnerability with remote code execution
#2Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.
Re: Cisco buffer overflow vulnerability with remote code execution
#3Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.
Re: Cisco buffer overflow vulnerability with remote code execution
#4Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.
Re: Cisco buffer overflow vulnerability with remote code execution
#5Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.
Given the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.
Re: Cisco buffer overflow vulnerability with remote code execution
#6There is also a Snort signature to detect attempts to exploit this vulnerability.
Re: Cisco buffer overflow vulnerability with remote code execution
#7Earlier quoted context omitted.
Given the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.
People who have firewall needs and no skills hire people who know what Cisco products are, get someone to implement an ASA for them, and then it sits for years without any software updates. Maybe a rule update every now and then, but definitely no software updates.
Our networking group automated a deployment for the fix and contacted everyone that has ever bought an ASA from our company and updated them. We have ~400 ASAs across the country still have Many of those clients have a maintenance agreement with us that includes these sorts of things and changes. All of them were updated and tested within 24 hours.
We did the same thing for the Juniper exploits (albeit we only had a handful).
EDIT: typos
Re: Cisco buffer overflow vulnerability with remote code execution
#8Here a nice explanation of the vulnerability: https://blog.exodusintel.com/2016/02/10/firewall-hacking/ There is also a Snort signature to detect attempts to exploit this vulnerability.