Week 3- Attackers Impersonate as Managed Devices
A report was created that a high-severity vulnerability has been found in Cisco's Nexus Dashboard Fabric Controller which allows unauthenticated attackers to impersonate managed network devices through SSH connections that are compromised. Security researchers from REQON B.V. identified the flaw, which comes from insufficient SSH host key validation mechanisms within the NDFC infrastructure. The affected system fails to properly validate SSH host keys during connection, that allows malicious actors to conduct machine-in-the-middle attacks giving themselves the chance to position themselves between the NDFC controller and managed devices, potentially intercepting and manipulating network management traffic. Attackers that successfully exploit this vulnerability could create persistent backdoors within the managed network environment. Cisco has released software updates to address this vulnerability, with no available workarounds for affected systems. The fix implements enhances the SSH host key valiadation to prevent unauthorized device impersonation attempts.
Source: https://cybersecuritynews.com/cisco-nexus-dashboard-fabric-controller-vulnerability/
Comments
Post a Comment