Vulnerabilities Weekly Summary Ending July 29

By Jerry Adams on July 29, 2016

This past week DNC’s emails were leaked and Cisco announced security advisories for several of its products.

DNC Email’s leaked

Big news this week are the leaked emails from the Democratic National Committee (DNC).  Though the contents of the leaked emails are what most people are talking about, the details of the hack are just as interesting.

It seems that the DNC’s network was hacked at least once before, last month.  The Washington Post reported on June 14, that hackers had gained access to an entire database of opposition research on Republican front-runner Donald Trump (

Shortly after the CrowdStrike report came out, a hacker who goes by the name Guccifer 2.0 claimed responsibility for the hack into the DNC networks.  He says he’s Romanian and hates being attributed to the Russians, stating, “I don’t like Russians and their foreign policy. I hate being attributed to Russia” (Franceschi-Bicchierai, L., 2016 Jun. 21, “We Spoke to DNC Hacker…“).  He said he left Russian metadata on the network, as his personal watermark and to throw off investigators.  Guccifer 2.0 claims he exploited a zero-day vulnerability in NGP VAN software used by the DNC to get into the network and from there installed Trojans on several of the Windows PC’s (Franceschi-Bicchierai, L., 2016 Jun. 21, “Here’s the Full Transcript…”).

However some cyber security experts are insisting that the hack into the DNC network was perpetrated by Russian hackers (Rid, T., 2016 Jul. 25).  In a report by ThreatConnect, Guccifer 2.0 is using a Russian based VPN service to communicate with the media.  This was discovered by analyzing the email headers and associated infrastructure Guccifer 2.0 is using.  ThreatConnect concluded that that Guccifer 2.0 is actually a Russian intelligence service disinformation and propaganda campaign and not an independent actor from Romania. (“Guccifer 2.0: All Roads Lead to Russia“, 2016 Jul. 25).

Cisco Security Advisories

Cisco announced security bulletins for six vulnerabilities affecting it’s products:

  • CVE-2016-1462 – vulnerability in the web-based management interface of the Cisco Prime Service Catalog (PSC).  An unauthenticated remote attacker could conduct a reflected cross-site scripting (XSS) by convincing a user to click a specific link. Vulnerability due to insufficient input validation of a user-supplied value. (“Cisco Security Advisory: Cisco Prime Service Catalog Reflected Cross-Site Scripting Vulnerability“, 2016 Jul. 27).
  • CVE-2016-1461 – A vulnerability in the Cisco AsyncOS for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause the  ESA to fail to detect and act upon a specific type of file that is attached to an email message.  The vulnerability is caused from improper use of message filtering rules on email attachments (“Cisco Security Advisory: Cisco Email Security Appliance File Type Filtering Vulnerability“, 2016 Jul. 27).
  • CVE-2016-1467 – A vulnerability in Cisco Videoscape Session Resource Manager (VSRM) could allow an unauthenticated attacker to cause a denial of service (DoS) from an adjacent network by unexpectedly restarting the device. The vulnerability can occur when the VSRM is not installed using best practices and in a secure environment where DoS attacks can be prevented. An attacker could exploit this vulnerability only by being on the adjacent network and directing a flood of traffic at the devices upstream to the VSRM (“Cisco Security Advisory: Cisco Videoscape Session Resource Manager Denial of Service Vulnerability“, 2016 Jul. 27).
  • CVE-2016-1460 – A vulnerability in Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) on the affected device. The vulnerability is due to insufficient handling of wireless management frames. An attacker could exploit this vulnerability by sending crafted wireless management frames to the device (“Cisco Security Advisory: Cisco Wireless LAN Controller Denial of Service Vulnerability“, 2016 Jul. 27).
  • CVE-2016-1465 – A vulnerability affecting Cisco Nexus 1000v Application Virtual Switch (AVS) could allow an unauthenticated, remote attacker to cause the ESXi hypervisor to crash and display a purple diagnostic screen, resulting in a denial of service (DoS). The vulnerability is due to insufficient input validation of Cisco Discovery Protocol packets, causing the ESXi hypervisor to crash due to an out-of-bound memory access. An attacker could exploit this vulnerability by sending a crafted Cisco Discovery Protocol packet to a targeted device causing a DoS condition (“Cisco Security Advisory: Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability“, 2016 Jul. 27).
  • CVE-2016-1463 – A vulnerability in Snort rule detection in Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass configured rules that use Snort detection.  The vulnerability is due to improper handling of HTTP header parameters. An attacker could send a crafted HTTP packet to the affected device, exploiting the vulnerability and bypassing configured Snort rules (“Cisco Security Advisory: Cisco FireSIGHT System Software Snort Rule Bypass Vulnerability“, 2016 Jul. 27).

As always please refer to our Patches and Updates page for links to the latest patches and security updates.

References:

(2016 Jul. 27). “Cisco Security Advisory: Cisco Prime Service Catalog Reflected Cross-Site Scripting Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-psc

(2016 Jul. 27). “Cisco Security Advisory: Cisco Email Security Appliance File Type Filtering Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-esa

(2016 Jul. 27). “Cisco Security Advisory: Cisco Videoscape Session Resource Manager Denial of Service Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-vsrm

(2016 Jul. 27). “Cisco Security Advisory: Cisco Wireless LAN Controller Denial of Service Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-wlc

(2016 Jul. 27). “Cisco Security Advisory: Cisco Nexus 1000v Application Virtual Switch Cisco Discovery Protocol Packet Processing Denial of Service Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-avs

(2016 Jul. 27). “Cisco Security Advisory: Cisco FireSIGHT System Software Snort Rule Bypass Vulnerability“. Cisco Systems Inc. Retrieved from http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160727-firesight

Russian government hackers penetrated DNC, stole opposition research on Trump“. The Washington Post. Retrieved from https://www.washingtonpost.com/world/national-security/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump/2016/06/14/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html

Alperovitch, D. (2016 Jun. 15).  “Bears in the Midst: Intrusion into the Democratic National Committee“. CrowdStrike. Retrieved from https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/

Franceschi-Bicchierai, L.  (2016 Jun. 21). “We Spoke to DNC Hacker ‘Guccifer 2.0‘”. Motherboard. Vice Media LLC. Retrieved from http://motherboard.vice.com/read/dnc-hacker-guccifer-20-interview

Franceschi-Bicchierai, L.  (2016 Jun. 21).  “Here’s the Full Transcript of Our Interview With DNC Hacker ‘Guccifer 2.0’“. Motherboard. Vice Media LLC. Retrieved from https://motherboard.vice.com/read/dnc-hacker-guccifer-20-full-interview-transcript

Rid, T. (2016 Jul. 25). “All Signs Point to Russia Being Behind the DNC Hack“. Motherboard. Vice Media LLC. Retrieved from http://motherboard.vice.com/en_uk/read/all-signs-point-to-russia-being-behind-the-dnc-hack

(2016 Jul. 25). “Guccifer 2.0: All Roads Lead to Russia“. ThreatConnect Inc. Retrieved from https://www.threatconnect.com/guccifer-2-all-roads-lead-russia/