Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

CVE-2020-27125, CVE-2020-27130, CVE-2020-27131: Pre-Authentication Vulnerabilities in Cisco Security Manager Disclosed

Following the publication of proof-of-concept (PoC) code, Cisco released three advisories for multiple vulnerabilities silently patched in a recent update. Organizations should apply these patches immediately.

Background

On November 16, Cisco published advisories for three vulnerabilities in Cisco Security Manager, a tool to monitor and manage a variety of Cisco devices, including Cisco Adaptive Security Appliances, Cisco Integrated Services Routers, Firewall Services Modules, Catalyst Series Switches and IPS Series Sensor Appliances. The vulnerabilities were discovered and disclosed by security researcher Florian Hauser of Code White.

Hauser originally tweeted about these vulnerabilities on November 11, saying that he had disclosed “12 vulnerabilities” to Cisco that affect the “web interface” of Cisco Security Manager. He noted that all of the vulnerabilities he disclosed were unauthenticated and “almost all directly giving RCE (Remote Code Execution).”

Five days later, on November 16, Hauser tweeted that because Cisco’s Product Security Incident Response Team (PSIRT) had become “unresponsive,” and because the alleged fixed version of Cisco Security Manager didn’t mention his disclosures, he decided to release his proof-of-concept (PoC) code for the 12 vulnerabilities.

Three advisories reportedly cover at least 12 vulnerabilities

Despite Hauser’s tweet describing 12 vulnerabilities, it appears that two of the CVEs, CVE-2020-27130 and CVE-2020-27131, encompass multiple vulnerabilities, which is why there isn’t a direct one to one match as far as CVEs are concerned.

Analysis

CVE-2020-27125 is a static credential vulnerability in Cisco Security Manager. An unauthenticated, remote attacker could obtain the static credentials by viewing the source code of a file. Successful exploitation would allow an attacker to use these static credentials to “carry out further attacks.” This vulnerability received a CVSSv3 score of 7.4 out of 10.0.

CVE-2020-27130 is a critical path traversal vulnerability in Cisco Security Manager. An unauthenticated, remote attacker could send a specially crafted request containing directory traversal character sequences (e.g. “../../”) to a vulnerable device. Successful exploitation would allow the attacker to arbitrarily download and upload files to the device. This vulnerability received a CVSSv3 score of 9.1 out of 10.0.

CVE-2020-27131 addresses multiple vulnerabilities in the Java deserialization function in Cisco Security Manager. An unauthenticated, remote attacker could exploit this vulnerability by generating malicious serialized Java objects using a tool like ysoerial.net and sending them as part of a specially crafted request to the vulnerable device. Successful exploitation would grant the attacker arbitrary code execution privileges on the device as NT AUTHORITY\SYSTEM. This vulnerability received a CVSSv3 score of 8.1 out of 10.0.

Research cites previous disclosure from Tenable’s Zero Day Research team

As part of his PoC release for CVE-2020-27131, Hauser included a reference to TRA-2017-23, a vulnerability disclosure from Tenable’s Zero Day Research team from 2017 regarding a deserialization remote code execution vulnerability in Cisco Security Manager and Cisco Prime LAN Management Solution.

Proof of concept

On November 16, Hauser tweeted a link to a GitHub gist that contains PoCs for the vulnerabilities he disclosed to Cisco. These PoCs include examples of serialized Java objects generated using ysoserial.

Solution

Cisco has released patches for CVE-2020-27125 and CVE-2020-27130. However, a patch for CVE-2020-271131 is not yet available. The following table provides insight into the affected versions and available fixes.

CVE Affected Versions Fixed Versions Fix Status
CVE-2020-27125 4.21 and earlier 4.22 and later Available
CVE-2020-27130 4.21 and earlier 4.22 and later Available
CVE-2020-27131 4.21 and earlier 4.23 and later Not Available

On November 17, Hauser tweeted that the fixes were “indeed implemented” and that they “need some further testing” with a Service Pack release expected within “the next few weeks.”

We will update this blog post once Cisco Security Manager 4.23 is available. Cisco has not provided any workarounds or mitigations for any of these vulnerabilities and notes that they are not aware of exploitation in the wild for these vulnerabilities at the time the advisories were published. The Security Response Team strongly encourages customers running Cisco Security Manager to upgrade to the most recent patched version as soon as possible.

Identifying affected systems

A list of Tenable plugins to identify these vulnerabilities will appear here as they’re released.

Get more information

Join Tenable's Security Response Team on the Tenable Community.

Learn more about Tenable, the first Cyber Exposure platform for holistic management of your modern attack surface.

Get a free 30-day trial of Tenable.io Vulnerability Management.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training