Rewterz

Rewterz Threat Alert – Dridex Banking Trojan – Active IOCs

June 3, 2021
Rewterz

Rewterz Threat Advisory – CVE-2021-26094 – FortiWLC – Multiple Buffer Overflow Vulnerabilities

June 3, 2021

Rewterz Threat Advisory – CVE-2021-1539; CVE-2021-1540 – Cisco ASR 5000 Series Software Authorization Bypass Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2021-1539

A vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass TACACS authorization on an affected device. An attacker could exploit this vulnerability by sending a crafted Secure Shell (SSH) request to an affected device. A successful exploit could allow the attacker to bypass TACACS authorization and execute a subset of CLI commands on the affected device.

CVE-2021-1540

A vulnerability in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker with an administrator account that is configured with the nocli option to bypass authorization on an affected device. An attacker could exploit this vulnerability by sending a crafted SSH request to an affected device. A successful exploit could allow the attacker to bypass the nocli option and execute a subset of CLI commands on the affected device.

Impact

  • Security Bypass
  • Unauthorized Access

Affected Vendors

Cisco

Affected Products

  • ASR 5000 Series Aggregation Services Router
  • Virtualized Packet Core Distributed Instance (VPC-DI)
  • Virtualized Packet Core Single Instance (VPC-SI)

Remediation

Refer to Cisco advisory for the complete list of affected product and their respective patches.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asr5k-autho-bypass-mJDF5S7n

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.