Hacking of Cisco servers serving the VIRL-PE infrastructure

Kompania Cisco revealed information about the hacking of 7 servers that support the network modeling system VIRL-PE (Virtual Internet Routing Lab Personal Edition), allowing the design and testing of network topologies based on Cisco's communication solutions without real equipment. The hack was detected on May 7. Control over the servers was gained through exploitation of a critical vulnerability in the SaltStack centralized configuration management system, which had previously been used to hack the infrastructures of LineageOS, Vates (Xen Orchestra), Algolia, Ghost, and DigiCert. The vulnerability also appeared in third-party installations of Cisco CML (Cisco Modeling Labs Corporate Edition) and Cisco VIRL-PE versions 1.5 and 1.6, if the user enabled salt-master.

Recall that on April 29, two vulnerabilities were fixed in Salt , allowing remote code execution on the controlling host (salt-master) and all managed servers without authentication.To execute the attack, network ports 4505 and 4506 must be accessible for external requests.
The GNAT Community 2020 has been released

Burimi: opennet.ru

Blini hosting të besueshëm për faqe interneti me mbrojtje nga DDoS, serverë VPS VDS 🔥 Blini hosting të besueshëm për faqe interneti me mbrojtje nga DDoS, serverë VPS VDS | ProHoster