TheaterFire

Cisco Security Breach

Posted by stevelife01@reddit | sysadmin | View on Reddit | 19 comments

Anyone familiar with this? For some reason it’s making big news in Canada regarding an SSL VPN vulnerability that’s apparently out in the wild.

Reply to Post

19 Comments

The_Original_Miser@reddit

Out of curiosity, how far does this vulnerability go back? i.e. would running an older version, say, something in the 9.1 range on an ASA 5505 (don't ask) be vulnerable?
View on Reddit #25462544

vc3ozNzmL7upbSVZ@reddit

7.2.6 is the fixed version for FTD, by the way.
View on Reddit #25311221

CompetitionFederal27@reddit

That’s correct, but you should be aware of CSCwi63113. It can cause a boot-loop if SNMP is enabled on the device (either immediately following the upgrade to 7.2.6 or if you reload manually). If you already upgraded you should consider disabling SNMP. 7.2.7 will have this fixed and should be released on May, 3rd. 7.2.5.2 will also fix the CVEs and be released by May, 6th
View on Reddit #25324341

vc3ozNzmL7upbSVZ@reddit

Too late :-). I guess we got lucky.
View on Reddit #25330091

RadagastVeck@reddit

Do you know if 7.4.1 is vulnerable too or has a fix planned?
View on Reddit #25328776

CompetitionFederal27@reddit

No, the both mentioned releases are the only one I have information about.
View on Reddit #25329785

DarkAlman@reddit

TLDR: Apparently this vulnerability was known by Cisco for 3-4 months before a patch was released for it, JFC Fixed version: **unknown** *There are firmware updates available for devices with the fix but the articles don't list the version, some require a TAC case to get the fixed versions. Patches are available for free if you don't have an active TAC contract. If someone replies with the fixed version I'll update the guide* **Determine Whether an ASA or FTD Device Is Affected** https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/ **Method 1: ** After updating the device to a software release that contains the fix for CVE-2024-20359, a review of the contents of disk0: should be conducted. If a new file (e.g., “client_bundle_install.zip” or any other unusual .zip file) appears on disk0: following the update, this suggests that Line Runner was present on the device in question. Note that because the updated software is not vulnerable to CVE-2024-20359, Line Runner will no longer be active on the device. **Method 2: ** To detect (and remove) Line Runner, the following series of commands will create an innocuous file with a .zip extension. Note that it will not create a valid zip file, but the file will still be read by the ASA at reboot. Upon execution of the following commands, if a new .zip file appears on disk0: following the reload, this suggests that Line Runner was present on the device in question. Deletion of the “client_bundle_install.zip” file will remove Line Runner. Note that the malicious ZIP containing the Line Runner functionality could have other names that fit the naming pattern outlined previously. If you discover a newly created .zip file, copy that file off the device using the copy command and contact psirt@cisco.com referencing CVE-2024-20359. Include the outputs of the dir disk0: and show version commands from the device and the .zip file extracted from the device.
View on Reddit #25281590

RadagastVeck@reddit

Leaving a comment and upvote so I find this tomorrow. Good work!
View on Reddit #25328307

nitrohigito@reddit

>The malware is persistent across reboots Only if the reboot is performed by the firmware; if you yank the power, the persistence feature of it will not be able to trigger.
View on Reddit #25319046

VA_Network_Nerd@reddit

For ASA on Firepower hardware the fixed-in release is: **`cisco-asa-fp2k.9.18.4.22.SPA`**
View on Reddit #25281862

Dariz5449@reddit

Well, it’s not a single fixed version only. It has patches all the way from 9.12 -> 9.20 All released, but 9.14 which needs TAC engagement. Same as well for FTD, most releases for patch but 7.1 as I recall.
View on Reddit #25282131

awesm_dawson@reddit

I see an update released for 9.14 as well
View on Reddit #25305285

sorean_4@reddit

Run the Cisco software checker. https://sec.cloudapps.cisco.com/security/center/softwarechecker.x
View on Reddit #25282582

Dariz5449@reddit

That’s one way, I’m just saying I know this is the case. Officially received this information through partner channels. Just wanting to clarify that it’s not only 9.18.
View on Reddit #25282708

DarkAlman@reddit

thanks, updated guide
View on Reddit #25282008

Nik_Tesla@reddit

We're not on Cisco ASAs anymore, but we've been getting hammered by failed login requests (presumably usernames and passwords from website leaks) from Russia for the past week or so. Either they're ramping up and going after anything and everything, or we were previously probed and got into a list of people with ASAs to attack.
View on Reddit #25297822

jmbpiano@reddit

> Either they're [...] going after anything and everything [...] It's this one. We've never had any Cisco equipment and we've been seeing the same attacks for a few weeks now. From [here](https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/): > Cisco Talos is actively monitoring a global increase in brute-force attacks against a variety of targets, including Virtual Private Network (VPN) services, web application authentication interfaces and SSH services since at least March 18, 2024. > [...] > Known affected services are listed below. However, additional services may be impacted by these attacks. > - Cisco Secure Firewall VPN > - Checkpoint VPN > - Fortinet VPN > - SonicWall VPN > - RD Web Services > - Miktrotik > - Draytek > - Ubiquiti
View on Reddit #25317261

CPAtech@reddit

https://www.reddit.com/r/Cisco/s/UAPxXKizeM
View on Reddit #25280684

VA_Network_Nerd@reddit

https://sec.cloudapps.cisco.com/security/center/publicationListing.x https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-websrvs-dos-X8gNucD2
View on Reddit #25279917