Cisco plugs critical password flaw in Common Services Platform Collector

Cisco is warning admins to install an update that addresses a static password bug in the Cisco Common Services Platform Collector (CSPC). 

The flaw, CVE-2019-1723, could be used by a remote attacker to log into a CSPC device using a static password for its default account. Cisco notes that the default account does not have administrative privileges. 

According to David Coomber, the researcher who reported the bug to Cisco, an attacker could access the CSPC via SSH or console and use the hardcoded credentials to gain a shell on the vulnerable system.

Coomber informed Cisco of the issue on February 14, just under a month before the new patch on Wednesday. The flaw affects Cisco CSPC releases 2.7.2 through 2.7.4.5 and all releases of 2.8.x prior to 2.8.1.2.

Admins may also need to update Cisco Smart Net Total Care (SmartNet) Network Collector and Cisco Partner Support Service (PSS) Network Collector, both of which use CSPC. The collector software collects information about other Cisco devices to produce inventory reports. 

The bug is fixed in Cisco CSPC 2.7.x branch with the release 2.7.4.6, while the issue is fixed in the CSPC 2.8.x branch in release 2.8.1.2.

The flaw has been given a rating of 9.8 out of 10 under the Common Vulnerability Scoring System (CVSS). 

Cisco notes there is a workaround for this bug however customers need to file a request with the Cisco Technical Assistance Center (TAC) or contact an engineer if they are subscribed to Cisco Network Optimization Service (NOS) or Cisco Business Critical Services (BCS). 

Cisco earlier this week warned that attackers were scanning for a separate critical flaw affecting the web interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router. 

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
CSO WANTED
Have an opinion on security? Want to have your articles published on CSO? Please contact CSO Content Manager for our guidelines.

Tags cisco

More about CiscoSmartSSHTAC

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Liam Tung

Latest Videos

More videos

Blog Posts