Cisco sneaks hardcoded secret root backdoor into vid surveillance kit
If you run Cisco's video surveillance kit, hop over to Switchzilla's support site and download the latest version of its management software.
Late last week, the networking giant admitted that its Cisco Video Surveillance Manager Appliance has an undocumented root account with static hard-coded credentials.
Reading between the lines, someone created the “secret” account during product development, and forgot about it: “The root account of the affected software was not disabled before Cisco installed the software on the vulnerable platforms.”
Because the hard-coded account has administrator-grade root privileges, an attacker able to reach the equipment over the network can do anything once they've logged in.
From its CVE-2018-15427 advisory: "A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the root account, which has default, static user credentials.
“This vulnerability affects Cisco Video Surveillance Manager (VSM) Software Releases 7.10, 7.11, and 7.11.1 if the software was preinstalled by Cisco and is running on the following Cisco Connected Safety and Security Unified Computing System (UCS) platforms: CPS-UCSM4-1RU-K9; CPS-UCSM4-2RU-K9; KIN-UCSM5-1RU-K9; KIN-UCSM5-2RU-K9.”
Products in the clear are releases earlier than VSM Software 7.9; later versions if they were installed as upgrades to VSM 7.9; or VSM Software VMWare's ESXi platform.
Industry: cyber security news
- Application Security Analyst
- Up to £85,000 Base
An Application Security Analyst is needed for an innovative commercial organisation in London. The Application Security Analyst will be working closely with the development team and should possess a blend of application security, development languages and Information Security skills. Application Security Analyst MUST have strong interpersonal skills. The Application Security Analyst role will include, but in no way be limited to; designing solutions to maintain security, whilst incorporating design solutions in Development, DevOps and Architectural best practices. Conduct application-level penetration testing and review security architecture of Product suite. Executing projects to implement a Security strategy. Knowledge / Experience should include; penetration testing consultancy, source code reviews, vulnerability management and security assessments. Experience with the following is desirable: Agile Development, Fortify 360 SCA, IBM Rational AppScan and exposure to security industry standards - ISO27001 and PCI-DSS. The ideal candidate will have 3 years’ experience in a similar Information Security role and have relevant security qualifications - CISM / CISSP or CISA etc. This is a client facing opportunity where you will be expected to travel to customer sites. Reference Number: OG7484 (Application Security, Penetration Testing, Information Security)
- Cloud Network Engineer
- Up to £35,000 Base + Bonus + Possible Share Options
One of our clients, an exciting UK based start-up is on the lookout for a Cloud Network Engineer in Yorkshire. The Cloud Network Engineer will need current CCNA / CCNP level networking experience (Cisco, BGP, IP etc.), cloud networking understanding (Azure, AWS etc.) and current experience ideally within a client facing / consultancy role. (Cloud Engineer, Network Engineer, Azure, AWS, Amazon Web Services) Reference Number: PG7477
- Senior Service Desk Analyst
- Up to £32,000 Base + £6,400 Shift Allowance
We are currently working on behalf of an IT Service Provider based in Wiltshire who are on the lookout for a Senior Service Desk Analyst. The Senior Service Desk Analyst will be responsible for logging, managing and escalating internal & external incidents and requests. This is an excellent opportunity to join a business recognised for what they do and work with a number of top UK businesses. You’ll be able to manage your career development and gain additional training e.g. certifications etc. This role will include a shift (4 days on then 4 days off) which covers 24/7 12 hour shifts The ideal candidate will be currently working in a IT service desk / IT support role ideally in an IT Services business. Reference Number: PG7476 (Service Desk Administrator, Analyst, Support, Service Desk Support, shift work, traning, Information Technology, Customer service, Customer support)
- Data Centre Service Delivery Manager
- Up to £50,000 + Package
A Data Centre Service Delivery Manager is needed to join a specialist connectivity provider in Hertfordshire. The company is going through a huge growth programme and this is an excellent opening for someone to join a business who are working with globally recognised organisations. You’ll be responsible for: Supporting the Commercial Director with management of existing and potential customers being the main point of contact. Maintaining and improving the company’s current and new services Customer relationship management Attending customer meetings in order to provide guidance to customers Keeping up a high quality level of service Updating appropriate documentation such as policy and procedures and making sure these are in place and followed Change and Incident management Service Level Agreements Experience required Must have current experience working in a Data centre environment in a Service Delivery role. An understanding of Data Centre technology and terminology. Experience of dealing with people of all levels within a business (Engineers to Board level) In return you'll have the ability to work in a cutting edge environment and work with a variety of well known international clients REF: PG7475