Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [NEWS] Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities |
|---|---|
| Date: | 9 Sep 2007 18:09:46 +0200 |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities ------------------------------------------------------------------------ SUMMARY Cisco Video Surveillance IP Gateway video encoder and decoder, Services Platform (SP), and Integrated Services Platform (ISP) devices contain authentication vulnerabilities that allow remote users with network connectivity to gain the complete administrative control of vulnerable devices. There are no workarounds for these vulnerabilities. DETAILS Affected Products Vulnerable Products These products are vulnerable: * Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware version 1.8.1 and earlier * Cisco Video Surveillance SP/ISP Decoder Software firmware version 1.11.0 and earlier * Cisco Video Surveillance SP/ISP firmware version 1.23.7 and earlier Users should consult their Stream Manager configuration management tool to determine the versions of firmware installed on deployed video surveillance devices. Products Confirmed Not Vulnerable No other Cisco products are currently known to be affected by these vulnerabilities. Details Cisco Video Surveillance IP Gateway video encoders and decoders allow the video feeds of cameras to be sent over an IP network. This function provides an upgrade path for users to convert from existing analog surveillance systems. Cisco Video Surveillance Services Platforms and Integrated Services Platforms record and aggregate video feeds received from IP Gateways. Stored video can be viewed and manipulated using the Cisco Video Surveillance Stream Manager software. * IP Gateway Encoder/Decoder Telnet Authentication Vulnerability: The Telnet server installed on Cisco Video Surveillance IP Gateway video encoders and decoders does not prompt for authentication. This may allow a remote user with network connectivity to gain interactive shell access with administrative privileges on vulnerable devices. This issue is documented in Cisco Bug ID <http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj31729> CSCsj31729 ( registered customers only) . * Services Platform/Integrated Services Platform Default Authentication Vulnerability: Cisco Video Surveillance Services Platform and Integrated Services Platform devices ship with default passwords for the sypixx and root user accounts. Users are not able to change these passwords due to application requirements. Users with knowledge of the default passwords may be able to gain interactive shell access with administrative privileges to vulnerable devices. This issue is documented in Cisco Bug ID <http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj34681> CSCsj34681 ( registered customers only) . Impact Successful exploitation of these vulnerabilities will result in the ability for a remote user to gain complete administrative access to vulnerable devices. An attacker with access to a vulnerable device may be able to view, alter, or delete video streams processed by the device, or cause a denial of service that may result in the loss of surveillance coverage. Workarounds There are no workarounds for these vulnerabilities. Filtering traffic to affected systems on screening devices can be used as a mitigation technique for both vulnerabilities. Access to the Telnet service (TCP port 23) on vulnerable devices should be restricted to authorized administration workstations. There is currently no method to configure filtering directly on IP Gateway encoders and decoders or Services Platform devices. Filters blocking access to TCP port 23 should be deployed at the network edge as part of a transit access list, which will protect the router where the access control list (ACL) is configured and also other devices behind it. Further information about transit access control lists is available in the white paper Transit Access Control Lists: Filtering at Your Edge, which is available at the following link: <http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801afc76.shtml> http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801afc76.shtml Additional mitigations that can be deployed on Cisco devices within the network are available in the Cisco Applied Intelligence companion document for this advisory: <http://www.cisco.com/warp/public/707/cisco-air-20070905-video.shtml> http://www.cisco.com/warp/public/707/cisco-air-20070905-video.shtml ADDITIONAL INFORMATION The information has been provided by <mailto:psirt@cisco.com> Cisco Systems Product Security Incident Response Team. The original article can be found at: <http://www.cisco.com/warp/public/707/cisco-sa-20070905-video.shtml> http://www.cisco.com/warp/public/707/cisco-sa-20070905-video.shtml ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [NEWS] Content Switching Module DoS Vulnerabilities, SecuriTeam |
|---|---|
| Next by Date: | [NT] Vulnerability in Microsoft Agent Allows Code Execution (MS07-051), SecuriTeam |
| Previous by Thread: | [NEWS] Content Switching Module DoS Vulnerabilities, SecuriTeam |
| Next by Thread: | [NT] Vulnerability in Microsoft Agent Allows Code Execution (MS07-051), SecuriTeam |
| Indexes: | [Date] [Thread] [Top] [All Lists] |