Skip to main content

Cisco IOS and IOS XE Software Cluster Management Protocol Remote Code Execution Vulnerability

A critical vulnerability in the Cisco Cluster Management Protocol (CMP) has been identified.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A critical vulnerability in the Cisco Cluster Management Protocol (CMP) has been identified.

Threat details

The Cluster Management Protocol uses Telnet internally as a signalling and command protocol between cluster members. The vulnerability is due to the combination of two factors:

  • The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members.
  • The incorrect processing of malformed CMP-specific Telnet options.

An attacker is able to send malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections.

Successful exploitation of this vulnerability could allow a remote, unauthenticated attacker to obtain full control of an affected device.


Remediation steps

Type Step
  • Disabling the Telnet protocol as an allowed protocol for incoming connections would eliminate the exploit vector.  
  • Customers unable or unwilling to disable the Telnet protocol can reduce the attack surface by implementing infrastructure access control lists (iACLs).

Last edited: 17 February 2020 11:28 am