Cisco coughs up baker's dozen of vulns and other security nasties

Get patching – except for the ones where you, er, can't

Cisco's six-monthly security update contains a baker's dozen of vulns and flaws in its IOS and IOS XE suites – including a backdoor that "could allow an unauthenticated, local attacker to bypass Cisco Secure Boot validation checks and load a compromised software image on an affected device".

The Cisco IOS ROM Monitor (ROMMON) package for its Catalyst 6800 series switches boils down to there being a "hidden command in the affected software", according to Cisco itself. By starting a console session on the affected device, an attacker could force it into ROMMON mode and write to a specific memory address on the device.

The bug was found during internal security testing, Cisco said.

If you are running Catalyst 6800 series Supervisor Engine 6T, Catalyst 6840-X series fixed backbone switches or Catalyst 6880-X series Extensible Fixed Aggregation Switches, now is a very good time to check Cisco's website for patches.

It was not immediately clear whether or not the company has released any patches for this, with the page on its website merely referring readers to a login-protected page.

For the other clutch of vulns, almost all the problems confessed to by Cisco are based on malformed packets being sent to devices running IOS and IOS XE triggering denial-of-service conditions or device resets.

One, however, affecting the Cisco Discovery Protocol module in IOS XE 16.6.1 and 16.6.2 "could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition".

A successful exploit, caused by sending "certain CDP packets to an affected device" could cause a cancer-style unstoppable consumption of all available memory leading to a memory allocation failure and a crash/reboot scenario.

Thankfully, a patch is available for CSCvf50648, as Cisco catchily numbered this particular nasty.

The full list is available here. ®

Broader topics

Other stories you might like

  • VMware claims ‘bare-metal’ performance from virtualized Nvidia GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual datacenter product updates across CPU, GPU, and DPU
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Now Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading

Biting the hand that feeds IT © 1998–2022