Cisco Patches Default SSH Key Virtual Appliance Vulnerabilities

Cisco has released a patch for three of its virtual appliances after it was discovered they contain default, authorised SSH keys that could allow an attacker virtually complete access to compromised systems.

The vulnerability affects all of Cisco’s Web Security Virtual Appliances (WSAv), Email Security Virtual Appliances (ESAv), and Content Security Management Virtual Appliances (SMav), and was found by Cisco during internal tests.

Two specific threats are mentioned by a Cisco advisory. The first allows an unauthenticated, remote attacker to connect to an affected system with root user privileges if they obtain the SSH key, while the second could permit a malicious user to decrypt and intercept secure communications via a man-in-the middle attack.

Cisco advisory

The company says there are no workarounds and there have been no attacks spotted in the wild, but has urged customers to download the patch through the usual software update mechanism.

“The patch will delete all the preinstalled SSH keys on the appliance,” it said. “After the key deletion, the patch will also provide customers with additional steps to take for a complete fix.”

Security experts have welcomed Cisco’s actions but are concerned about the potential scale of the vulnerability.

“To truly understand the scope of impact for this vulnerability, we’d have to know the number of these devices actually deployed,” said Tim Erlin, Director of Security and Product Management at Tripwire. “It’s great that there’s an update to address the issue, but customers must actually apply it to be protected. There’s often a lag between update availability and effective deployment, creating a window of risk.

“Because this affects virtual images, it’s entirely possible that some may lay dormant through the initial update cycle, then introduce the vulnerability at a later date when started.”

Take our hacking and viruses quiz here!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

22 hours ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

24 hours ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

1 day ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

2 days ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

2 days ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

2 days ago