Live data from Hacker News

Cisco buffer overflow vulnerability with remote code execution

tools.cisco.com

1–10 of 23 posts

Re: Cisco buffer overflow vulnerability with remote code execution

#3
post #2

Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.

Given the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.

Re: Cisco buffer overflow vulnerability with remote code execution

#4
post #2

Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.

That isn't true. There are versions of 9.2.x, 9.3.x etc that are vulnerable per the documentation. 9.1.7 is the only firmware released before this was announced (jan 18th) that contains a fix. Every other software version is vulnerable and requires an upgrade.

Re: Cisco buffer overflow vulnerability with remote code execution

#5
post #3
post #2

Edit...this is wrong-> It's specific to Cisco ASA firewalls with a version level Edit: Gelob, below, is right. There's a really unfortunate "read more" link that hides the important bits on Cisco's documentation and caused my confusion.

Given the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.

People who have firewall needs and no skills hire people who know what Cisco products are, get someone to implement an ASA for them, and then it sits for years without any software updates. Maybe a rule update every now and then, but definitely no software updates.

Re: Cisco buffer overflow vulnerability with remote code execution

#7
post #5
post #3

Earlier quoted context omitted.

Given the tendency for large enterprises to not upgrade unless there is time to do a full regression test, and then to prioritize creating new features over system maintenance, I wouldn't assume that means that there aren't quite a few of those still out there.

People who have firewall needs and no skills hire people who know what Cisco products are, get someone to implement an ASA for them, and then it sits for years without any software updates. Maybe a rule update every now and then, but definitely no software updates.

Perhaps most do but I see a different trend these days. "The network" is a lot more important now since so many things are cloud-based.

Our networking group automated a deployment for the fix and contacted everyone that has ever bought an ASA from our company and updated them. We have ~400 ASAs across the country still have Many of those clients have a maintenance agreement with us that includes these sorts of things and changes. All of them were updated and tested within 24 hours.

We did the same thing for the Juniper exploits (albeit we only had a handful).

EDIT: typos

Re: Cisco buffer overflow vulnerability with remote code execution

#9
Cisco was also rushed to release the fix, as all of the new builds are tagged 'interim' and warn users that they have bugs and stability problems that will be fixed later. Most notably, several issues with ASA Clustering were found in the new builds. So you're damned if you do, damned if you don't.
Post reply on HN