Hack of Cisco servers supporting the VIRL-PE infrastructure

Cisco revealed details about the hack of 7 servers that provide functionality for network modeling system VIRL-PE (Virtual Internet Routing Lab Personal Edition), which allows the design and testing of network topologies based on Cisco communication solutions without real hardware. The breach was detected on May 7. Control over the servers was gained by exploiting a critical vulnerability in the centralized configuration management system SaltStack, which had previously been used to hack the infrastructures of LineageOS, Vates (Xen Orchestra), Algolia, Ghost, and DigiCert. The vulnerability also manifested in third-party installations of Cisco CML (Cisco Modeling Labs Corporate Edition) and Cisco VIRL-PE versions 1.5 and 1.6, if the user enabled salt-master.

It should be noted that on April 29, two vulnerabilities were fixed in Salt, allowing remote code execution on the management host (salt-master) and all servers managed through it without authentication.
For the attack, network ports 4505 and 4506 must be accessible for external requests.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster