{"id":17840,"date":"2020-06-01T11:55:00","date_gmt":"2020-06-01T11:55:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2576421"},"modified":"2020-06-01T11:55:00","modified_gmt":"2020-06-01T11:55:00","slug":"cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2","status":"publish","type":"post","link":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/","title":{"rendered":"Cisco security breach hits corporate servers that ran unpatched software"},"content":{"rendered":"<h2>Cisco is one of many to get bitten by vulnerabilities in open source Salt manager.<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg\" alt=\"Cisco security breach hits corporate servers that ran unpatched software\" width=\"706\" height=\"504\" \/><\/p>\n<section class=\"post-meta\">\n<p>Six servers Cisco uses to provide a virtual networking service were compromised by hackers who exploited critical flaws contained in unpatched versions the open source software service relies on, the company disclosed on Thursday.<\/p>\n<h2>Got updates?<\/h2>\n<p>The May 7 compromise hit six Cisco servers that provide backend connectivity to the Virtual Internet Routing Lab Personal Edition (VIRL-PE), a Cisco service that lets customers design and test network topologies without having to deploy actual equipment. Both the VIRL-PE and a related service, Cisco Modeling Labs Corporate Edition, incorporate the&nbsp;<a href=\"https:\/\/github.com\/saltstack\/salt\">Salt management framework<\/a>, which contained a pair of bugs that, when combined, was critical. The vulnerabilities became&nbsp;<a href=\"https:\/\/lists.opensuse.org\/opensuse-security-announce\/2020-04\/msg00047.html\">public on April 30<\/a>.<\/p>\n<p>Cisco deployed the vulnerable servers on May 7, and they were compromised the same day. Cisco took them down and remediated them, also on May 7. The servers were:<\/p>\n<ul>\n<li>us-1.virl.info<\/li>\n<li>us-2.virl.info<\/li>\n<li>us-3.virl.info<\/li>\n<li>us-4.virl.info<\/li>\n<li>vsm-us-1.virl.info<\/li>\n<li>vsm-us-2.virl.info<\/li>\n<\/ul>\n<p>Cisco said that without updates, any VIRL-PE or CML products that are deployed in standalone or cluster configurations will remain vulnerable to the same sorts of compromises. The company released software updates for the two vulnerable products. Cisco rated the severity of the vulnerabilities with a ranking of 10 out of 10 on the&nbsp;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Common_Vulnerability_Scoring_System\">CVSS scale<\/a>.<\/p>\n<p>The Salt vulnerabilities are&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-11651\">CVE-2020-11651<\/a>, an authentication bypass, and&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-11652\">CVE-2020-11652<\/a>, a directory traversal. Together, they allow unauthorized access to the entire file system of the master salt server that services using Salt rely on. F-Secure, the firm that discovered the vulnerabilities, has a good description of them&nbsp;<a href=\"https:\/\/labs.f-secure.com\/advisories\/saltstack-authorization-bypass\">here<\/a>.<\/p>\n<h2>Join the club<\/h2>\n<p>Cisco and its customers are just a small sampling of those who have been bitten by the Salt bugs in recent weeks. Early this month, blogging platform Ghost reported hackers had exploited the flaw to&nbsp;<a href=\"https:\/\/ghost.org\/faq\/salt-incident\/\">infect servers in its private network<\/a>&nbsp;with currency-mining malware on its servers.<\/p>\n<p>Other groups that have also been affected include&nbsp;<a href=\"https:\/\/www.digicert.com\/digicert-statement-on-ct2-log\/\">Digicert<\/a>,&nbsp;<a href=\"https:\/\/status.lineageos.org\/issues\/5eae596b4a0ebd114676545f\">LineageOS<\/a>, and&nbsp;<a href=\"https:\/\/twitter.com\/xenorchestra\/status\/1257274022477389831\">Xen Orchestra<\/a>.<\/p>\n<p>The string of attacks on such a varied list of targets underscores the interconnectedness of Internet services today. A critical vulnerability in one piece can often quickly ripple out. Anyone using software or services that rely on Salt&mdash;whether Cisco or otherwise&mdash;would do well to make sure they have been updated.<\/p>\n<\/section>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"https:\/\/github.com\/saltstack\/salt\" target=\"_blank\">https:\/\/github.com\/saltstack\/salt<\/a><br \/><b>Contact Information:<\/b><br \/>DAN GOODIN<\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/artificial-intelligence-newswire\/\" rel=\"category tag\">Artificial Intelligence Newswire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>DAN GOODIN<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cisco is one of many to get bitten by vulnerabilities in open source Salt manager. Six servers Cisco uses to provide a virtual networking service were compromised by hackers who exploited critical flaws contained in unpatched versions the open source software service relies on, the company disclosed on Thursday. Got updates? The May 7 compromise &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\">Continue reading <span>Cisco security breach hits corporate servers that ran unpatched software<\/span><\/a> <a href=\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":47,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,3,22,54],"tags":[],"class_list":["post-17840","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence-newswire","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cisco security breach hits corporate servers that ran unpatched software - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cisco security breach hits corporate servers that ran unpatched software - Business\" \/>\n<meta property=\"og:description\" content=\"Cisco is one of many to get bitten by vulnerabilities in open source Salt manager. Six servers Cisco uses to provide a virtual networking service were compromised by hackers who exploited critical flaws contained in unpatched versions the open source software service relies on, the company disclosed on Thursday. Got updates? The May 7 compromise &hellip; Continue reading Cisco security breach hits corporate servers that ran unpatched software Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-01T11:55:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg\" \/>\n<meta name=\"author\" content=\"Bilal\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bilal\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\",\"url\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\",\"name\":\"Cisco security breach hits corporate servers that ran unpatched software - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg\",\"datePublished\":\"2020-06-01T11:55:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20\"},\"breadcrumb\":{\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage\",\"url\":\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg\",\"contentUrl\":\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cisco security breach hits corporate servers that ran unpatched software\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20\",\"name\":\"Bilal\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g\",\"caption\":\"Bilal\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"https:\/\/ipsnews.net\/business\/author\/bilal\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cisco security breach hits corporate servers that ran unpatched software - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/","og_locale":"en_US","og_type":"article","og_title":"Cisco security breach hits corporate servers that ran unpatched software - Business","og_description":"Cisco is one of many to get bitten by vulnerabilities in open source Salt manager. Six servers Cisco uses to provide a virtual networking service were compromised by hackers who exploited critical flaws contained in unpatched versions the open source software service relies on, the company disclosed on Thursday. Got updates? The May 7 compromise &hellip; Continue reading Cisco security breach hits corporate servers that ran unpatched software Continue Reading &rarr;","og_url":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/","og_site_name":"Business","article_published_time":"2020-06-01T11:55:00+00:00","og_image":[{"url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg","type":"","width":"","height":""}],"author":"Bilal","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bilal","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/","url":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/","name":"Cisco security breach hits corporate servers that ran unpatched software - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage"},"image":{"@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg","datePublished":"2020-06-01T11:55:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20"},"breadcrumb":{"@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#primaryimage","url":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg","contentUrl":"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2017\/01\/cisco-800x571.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/ipsnews.net\/business\/2020\/06\/01\/cisco-security-breach-hits-corporate-servers-that-ran-unpatched-software-2\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"Cisco security breach hits corporate servers that ran unpatched software"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20","name":"Bilal","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g","caption":"Bilal"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"https:\/\/ipsnews.net\/business\/author\/bilal\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=17840"}],"version-history":[{"count":1,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17840\/revisions"}],"predecessor-version":[{"id":17841,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/17840\/revisions\/17841"}],"wp:attachment":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=17840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=17840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=17840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}