Cisco sneaks hardcoded secret root backdoor into vid surveillance kit
If you run Cisco's video surveillance kit, hop over to Switchzilla's support site and download the latest version of its management software.
Late last week, the networking giant admitted that its Cisco Video Surveillance Manager Appliance has an undocumented root account with static hard-coded credentials.
Reading between the lines, someone created the “secret” account during product development, and forgot about it: “The root account of the affected software was not disabled before Cisco installed the software on the vulnerable platforms.”
Because the hard-coded account has administrator-grade root privileges, an attacker able to reach the equipment over the network can do anything once they've logged in.
From its CVE-2018-15427 advisory: "A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials.
“This vulnerability affects Cisco Video Surveillance Manager (VSM) Software Releases 7.10, 7.11, and 7.11.1 if the software was preinstalled by Cisco and is running on the following Cisco Connected Safety and Security Unified Computing System (UCS) platforms: CPS-UCSM4-1RU-K9; CPS-UCSM4-2RU-K9; KIN-UCSM5-1RU-K9; KIN-UCSM5-2RU-K9.”
Products in the clear are releases earlier than VSM Software 7.9; later versions if they were installed as upgrades to VSM 7.9; or VSM Software VMWare's ESXi platform.
Industry: cyber security news
- Senior SOC Analyst
- Up to £55,000 Basic
Senior SOC Analyst is needed to join an established cyber security business. The individual must be able to commute to Surrey / Hampshire area. The Senior SOC Analyst must have current experience working within a cyber security environment with the following experience; Acting as the point of escalations for the team and external clients to help eliminate & prevent security incidents. SIEM monitoring, design & implementation. Developing & Strengthening current client services As the business continues to evolve the board are looking to attract the right candidate to help them to continue to expand their capabilities and offerings. Unfortunately this opportunity is unable to provide sponsorship. Reference Number: CH7421
- Junior Sales Consultant
- Up to £35,000 Base + Double Uncapped OTE
A Junior Sales Consultant is needed for a UK focussed managed service provider in London who have grown by over 25% this year. The Junior Sales Consultant will be responsible for identifying and closing new business opportunities with the Small Medium Enterprise (SME) market. The ideal Junior Sales Consultant will possess; Current experience selling cloud solutions (Azure, AWS etc.) within the SME market. Track record reaching and beating targets. Appetite to learn and make money. Unfortunately our client is unable to sponsor for this role. Reference Number: PG7423
- Technical Support Lead
- Up to £50,000 Basic
A Technical Support Lead is needed to join a organically growing UK focussed managed service provider company in London The Technical Support Lead will be responsible for all things technical support (internal teams & external clients) e.g. 3rd level support, deployments and also growing the current team. The ideal Technical Support Lead will possess; Current experience within a 3rd line support role with a focus on Microsoft technologies (Hyper V, Server, Azure etc.) Certifications such as Microsoft Certified Professional (MCP), Microsoft Certified Solutions Associate (MCSA) or Microsoft Certified Solutions Expert (MCSE) certifications. This would be a great chance for someone in a 3rd Line Support role to take the next step and be given the opportunity to lead and grow a team and join a company who have grown by over 25% this year. Unfortunately our client is unable to sponsor for this role. Reference Number: PG7422
- Cloud Channel Manager
- Up to £75,000 Base dependant on experience + Double OTE
A Cloud Channel Manager is needed for a Leading Cloud Service Provider in London due to increased customer demand. The Cloud Channel Manager will be primarily responsible for rebuilding & protecting current accounts and also new logo sales into the channel e.g. Value Added Resellers (VAR) / Managed Service Providers (MSP), SI etc. Requirements Current experience selling Cloud technology such as AWS / Azure into the channel Over achieved on sales targets. Long tenure (3/4 years+) in current and previous positions. Reference Number: PG7419