Cisco Discloses Security Breach That Impacted VIRL-PE Infrastructure

cisco.png

Cisco has disclosed today a security breach that impacted a small part of its backend infrastructure.

In a security alert published today, Cisco said that hackers used a vulnerability in the SaltStack software package, which Cisco bundles with some products, to gain access to six servers:

  • us-1.virl.info
  • us-2.virl.info
  • us-3.virl.info
  • us-4.virl.info
  • vsm-us-1.virl.info
  • vsm-us-2.virl.info

The six servers provide the backend infrastructure for VIRL-PE (Internet Routing Lab Personal Edition), a Cisco service that lets users model and create virtual network architectures to test network setups before deploying equipment in real situations.

"Cisco identified that the Cisco maintained salt-master servers that are servicing Cisco VIRL-PE releases 1.2 and 1.3 were compromised," the company said today.

Cisco said it patched and remediated all hacked VIRL-PE servers on May 7, when it deployed updates for the SaltStack software.

Cisco customers with CML and VIRL-PE gear also impacted

However, the issue isn't localized to Cisco's backend infrastructure alone.

Cisco says that two of its commercial products also bundle the SaltStack software package as part of their firmware. These are the aforementioned Cisco VIRL-PE, and Cisco Modeling Labs Corporate Edition (CML), another network modeling tool.

Both VIRL-PE and CML can be used in Cisco-hosted and on-premis scenarios. In case companies use the two products on location, Cisco says CML and VIRL-PE need to be patched.

The company has released software updates today for both products that incorporate fixes for the two SaltStack vulnerabilities that were utilized to breach Cisco's VIRL-PE backend.

The two SaltStack vulnerabilities -- CVE-2020-11651 (an authentication bypass) and CVE-2020-11652 (a directory traversal) -- have been disclosed on April 30, and have been heavily abused over the past month.

Security breaches caused by the two have been reported by mobile operating system vendor LineageOS, blogging platform Ghost, certificate authority Digicert, cloud software provider Xen Orchestra, and search provider Algolia.

In most of the past incidents, victims said the hacker breached SaltStack servers and installed a cryptocurrency miner. Cisco did not elaborate on the nature of its breach.

SaltStack, also known as Salt, is a type of software used in data centers that allows administrators to cluster multiple servers together and control them from a central location.

The Cisco security advisory Cisco-SA-Salt-2vx545AG contains all the necessary information for Cisco CML and VIRL-PE users to patch their devices.

RECENT NEWS

SEC's Oversight Over Digital Assets: Balancing Regulation And Innovation

As the digital asset market continues to expand, regulatory agencies like the Securities and Exchange Commission (SEC) a... Read more

Harnessing AI To Combat Cyber Risk: Strategies For Financial Institutions

Cyber threats pose an ever-present danger to financial institutions, requiring robust strategies to mitigate risks effec... Read more

Adaptation And Innovation: Revolut's Response To Banking License Delay Through Advertising Sales Push

As Revolut eagerly awaits the acquisition of its banking license, the fintech giant has demonstrated remarkable adaptabi... Read more

Riding The Wave: The Evolution Of Fintech Investment Strategies

The fintech industry has experienced unprecedented growth in recent years, captivating the attention of investors worldw... Read more

How Fintech Is Revolutionizing Traditional Banking

How fintech is revolutionizing traditional banking is a topic that is garnering positive and immense discourse within th... Read more

Blockchain And Its Impact On Fintech Industry

Blockchain and its impact on Fintech Industry has become a hot topic in the current digital era. The amalgamation of blo... Read more