IOW...
"Governments issue alerts after fourteen-year-old script kiddie finds NSA backdoor built into Cisco security boxes"
A previously unknown and "sophisticated" nation-state group compromised Cisco firewalls as early as November 2023 for espionage purposes — and possibly attacked network devices made by other vendors including Microsoft, according to warnings from the networking giant and three Western governments. These cyber-spy campaigns, …
"Line Dancer can also trick the AAA (Authentication, Authorization and Accounting) function into allowing the attacker to connect using a magic number authentication capability to establish a remote access VPN tunnel."
Wouldn't the word 'password' have been much quicker to type? Or is it much more subtle?
Closed source at work here..................
..........of course, the patch to "fix" this problem will almost certainly include a replacement "weakness"!!!!
Quote: (William Burroughs) "The paranoid is a person who knows a little of what is going on."
I stopped using cisco ASA around v5.2ish and old IOS @ 12.3 as it was an unsecure pos and found it highly annoying you had to repeatedly pay for their next backdoored code version. I suppose somebody has to pay for the devs to think up new ways to obfuscate the *required holes in their system.Those using cisco gear are the same breed as the lemmings that continue to jump off Microsoft's cliffs despite the escalating numbers of injured. *Plenty of information out there for you to see.
Two months since the last cisco backdoor discovery.
"first spotted in early January and revealed on Wednesday."
Is this because they've released patched to block the intrusions or did it just take this long to get around to telling people their security is leaking like a sieve?
I can understand a delay in announcing a vuln that's not being actively exploited since that would give the bad guys a clear window of opportunity while the fix is being developed, but when it's an actively exploited vuln, would it not be better to announce it ASAP so at least the victims and potential can try to do something to protect themselves?