Cisco details about the hack of 7 servers that provide functionality for network modeling system (Virtual Internet Routing Lab Personal Edition), which allows the design and testing of network topologies based on Cisco communication solutions without real hardware. The breach was detected on May 7. Control over the servers was gained by exploiting a critical vulnerability in the centralized configuration management system SaltStack, which had previously to hack the infrastructures of LineageOS, Vates (Xen Orchestra), Algolia, Ghost, and DigiCert. The vulnerability also manifested in third-party installations of Cisco CML (Cisco Modeling Labs Corporate Edition) and Cisco VIRL-PE versions 1.5 and 1.6, if the user enabled salt-master.
It should be noted that on April 29, two vulnerabilities , allowing remote code execution on the management host (salt-master) and all servers managed through it without authentication.
For the attack, network ports 4505 and 4506 must be accessible for external requests.
Source: opennet.ru
