Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The Cluster Management Protocol uses Telnet internally as a signalling and command protocol between cluster members. The vulnerability is due to the combination of two factors:
- The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members.
- The incorrect processing of malformed CMP-specific Telnet options.
An attacker is able to send malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections.
Successful exploitation of this vulnerability could allow a remote, unauthenticated attacker to obtain full control of an affected device.
Remediation steps
Last edited: 17 February 2020 11:28 am