Cisco released a security update to address high-rated vulnerabilities affecting Cisco Identity Services Engine (ISE) and with Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices, according to a report with US-CERT.

In one issue, there is a vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is because of an insufficient validation of client-supplied parameters while establishing an SSL VPN session. An attacker could exploit this vulnerability by crafting a malicious request and sending it to the affected device.

A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to crash and restart, resulting in the failure of the established SSL VPN connections and forcing remote users to initiate a new VPN connection and re-authenticate. A sustained attack could prevent new SSL VPN connections from being established.

When the attack traffic stops, the Cisco AnyConnect VPN server recovers gracefully without requiring manual intervention.

Schneider Bold

Cisco Meraki released software updates that address this vulnerability, according to an advisory. There are no workarounds that address this vulnerability.

This vulnerability affects the following Cisco Meraki products if they are running a vulnerable release of Cisco Meraki MX firmware and have Cisco AnyConnect VPN enabled:

  • MX64
  • MX64W
  • MX65
  • MX65W
  • MX67
  • MX67CW
  • MX67W
  • MX68
  • MX68CW
  • MX68W
  • MX75
  • MX84
  • MX85
  • MX95
  • MX100
  • MX105
  • MX250
  • MX400
  • MX450
  • MX600
  • vMX
  • Z3C
  • Z3

Cisco AnyConnect VPN is supported on Cisco Meraki MX Series and Cisco Meraki Z3 Teleworker Gateway devices that run Cisco Meraki MX firmware releases 16.2 and later, except for Cisco Meraki MX64 and MX65, which support Cisco AnyConnect VPN only if they are running Cisco Meraki MX firmware releases 17.6 and later.

Cisco Meraki MX Series and Cisco Meraki Z3 Teleworker Gateway devices support the following two VPN services for remote network access:

  1. Client VPN, which uses Layer 2 Tunneling Protocol (L2TP) or IPsec tunneling protocols
  2. Cisco AnyConnect VPN, which uses Transport Layer Security (TLS) and Datagram TLS (DTLS) protocols and is commonly referred to as SSL VPN

On Cisco Meraki MX Series and Cisco Meraki Z3 Teleworker Gateway devices, Client VPN (L2TP/IPsec) and Cisco AnyConnect VPN (SSL) services can be enabled simultaneously.

This vulnerability resides in the processing of TLS and DTLS packets, so it affects only devices configured with Cisco AnyConnect VPN. Devices that are configured to provide remote network access exclusively through Client VPN (L2TP/IPsec) are not affected by this vulnerability.

There are no workarounds that address this vulnerability. Cisco Meraki recommends administrators upgrade devices to a fixed software release. Disabling Cisco AnyConnect VPN will remove the attack vector for the vulnerability that is described in this advisory.

For Cisco Meraki MX Firmware, the issue does not affect versions earlier than 16.2. For versions 16.2 and later, users should update to version 16.16.6. For versions 17.x, users should update to version 17.10.1.

In another issue, there is a vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) that could allow an authenticated, remote attacker to read and delete files on an affected device.

This vulnerability is because of insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains certain character sequences to an affected system. A successful exploit could allow the attacker to read or delete specific files on the device their configured administrative level should not have access to.

Cisco does have a plan to release software updates that address this vulnerability, according to the advisory. There are no workarounds that address this vulnerability.

This vulnerability affects Cisco ISE. For version 3.0 and earlier, it is not vulnerable. For versions 3.1-3.1P5 an update will release in November. For versions 3.2-3.2P1, an update will release in January next year. For versions 3.1 and 3.2, hot patches may be available by request.

Click here for more information on other Cisco security updates.

ISSSource

Pin It on Pinterest

Share This