Site navigation

NCSC Warns About Cisco SD-WAN Zero Day Vulnerability

Elizabeth Greenberg

,

cisco zero-day
Cyber agencies are urging an urgent patch for a network zero-day vulnerability.

Cybersecurity agencies including the National Cyber Security Centre are warning about the potential compromise of Cisco Catalyst SD-WAN, encouraging an immediate investigation into the globally-used network.

Malicious cyber threat actors are targeting Cisco Catalyst Software Defined Wide Area Networks (SD-WAN) used by organisations globally.

These actors are compromising SD-WANs to add a malicious rogue peer and then conduct a range of follow-on actions to achieve root access and maintain persistent access to the SD-WAN.

This cluster of cyber threat activity has targeted organisations using Cisco Catalyst SD-WANs globally.

A Hunt Guide has been prepared based on observations from various investigations which details tactics, techniques, and procedures (TTPs) leveraged by these malicious actors. The Hunt Guide aims to support network defenders to conduct detection and threat hunting activities and provides mitigation guidance to reduce the risk from the observed TTPs.

The Hunt Guide is being released and co-signed by a range of agencies, including those in Australia, Canada, New Zealand, the UK, and the US.

Cisco has released software updates for Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller.

Organisations employing Cisco Catalyst SD-WAN could be affected, and should follow the priority actions detailed below.

Cisco Catalyst SD-WANs that have management interfaces exposed to the internet are at most risk of compromise, the NCSC warns. These management interfaces must never be exposed to the internet.

Network defenders are urged to follow certain priority actions, including:

  1. Threat hunting for evidence of compromise detailed in the Hunt Guide.
  2. If you believe you have been compromised, collect artefacts from the device and, if you are in the UK, report it to the NCSC.
  3. Update to the appropriate fixed latest version of Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller as detailed in their respective advisories.
  4. Apply the Cisco Catalyst SD-WAN Hardening Guide.
  5. Perform continuous threat hunting activities.

To reduce the risks to any network, organisations are encouraged to take appropriate action based on the Cisco Catalyst SD-WAN Hardening Guide.


Recommended reading


Actions could include securing network perimeter controls, reconfiguring SD-WAN manager access, using pairwise keying on data plane security, limiting session timeouts to the shortest possible periods, and using a remote syslog server for logging.

The NCSC has said that any of its proposed mitigation or eviction measures are subject to change as new information becomes available and ongoing coordinated operated dictate.

Network defenders should ensure any actions taken in response to the Hunt Guide are compliant with local laws and regulations within the jurisdictions within which they operate.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data