Cisco Confirms Switches Exploited by CIA via CMP Flaw; Fix Coming Soon

Advertisement
By Tasneem Akolawala | Updated: 5 April 2017 17:10 IST
Highlights
  • The company claims that the vulnerability is in CMP processing code
  • An exploit can be avoided by disabling telnet
  • Cisco promises a fix soon

Last week, WikiLeaks claimed that the CIA had exploited various apps, platforms, and devices unethically to spy on people. One of the affected tech companies was Cisco, whose switches were hacked by CIA to remotely exercise control. The company has now confirmed that as many as 318 Cisco switches have a vulnerability that can allow the CIA to remotely execute malicious code and gain full control on the device.

The company issued an advisory on the matter, and claimed that currently there are "no workaround that address this vulnerability," but it's looking to roll out a fix soon. Cisco discovered the vulnerability in the Vault 7 dump by WikiLeaks.

The advisory claims that the vulnerability is in the "Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software, and it could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges."

Advertisement

It essentially stems from a "failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and the incorrect processing of malformed CMP-specific Telnet options."

Advertisement

Cisco hasn't announced when the fix is coming, but has mentioned a few things for users to do to avoid hackers from taking advantage. It recommends disabling Telnet and using SSH, and has also detailed guidelines for doing it on this support page. Users who are unable or unwilling to disable the Telnet protocol can reduce the attack surface by implementing infrastructure access control lists (iACLs). Guidelines on that can be found on this support page.

WikiLeaks recently announced that it will work with technology companies to give them technical details to work on fixes of CIA exploits. Other tech giants affected by the CIA hacking are Apple, Microsoft, Samsung, and more.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. MacBook Air (2025) With M4 Chip Available at This Discounted Price
  2. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  3. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  4. Logitech MX Master 4 Launches in India With These Features
  5. Oppo Reno 15c With Snapdragon 7 Gen 4 SoC Launched at This Price
  6. All the Details About Kunal Khemu's Comedy Drama 'Single Papa'
  7. ChatGPT's Adult Mode Might Arrive in Early 2026
  8. K-Pop, Bollywood, Podcasts: Here's What Indian Users Asked Alexa in 2025
  9. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  10. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  1. Clair Obscur: Expedition 33 Gets New 'Thank You' Update After Winning at The Game Awards
  2. Apple Fitness+ Now Available in India With Custom Workout Programmes: Price and Other Details
  3. Samsung Could Reportedly Strike a Deal With AMD to Build Future 2nm Process Chipsets
  4. Pixel 10 Series, Pixel Accessories Get Price Cuts in India During Google's End of Year Sale
  5. Alexa's Popular Requests in 2025 Included K-Pop, Bollywood, Podcasts and Details About Celebrities
  6. Logitech MX Master 4 Launched in India With 8,000 DPI Sensor and Multi-Pairing Support
  7. Amazon Introduces Ask This Book AI Feature for the Kindle App, Provides Spoiler-Free Answers
  8. MacBook Air (2025) With M4 Chip Available With Over Rs. 10,000 Discount in India: Here Are the Details
  9. Oppo Reno 15c Launched With Snapdragon 7 Gen 4 SoC, 6,500mAh Battery: Price, Specifications
  10. Star Wars: Fate of the Old Republic Will Launch Before 2030, Game Director Confirms
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.