IFP Exclusive

Iranian Databases Target of Attacks Caused by Cisco Switch Flaw

A flaw in Cisco switches has allowed hackers to target critical infrastructure in many countries with cyberattacks including Iran.

Reports say that important Iranian services and websites have become out of reach due to a problem in the datacentres of major internet service providers Afranet, Shatel, Sabanet, etc.

According to a security report from the Cisco Talos team as many as 168,000 systems in the world may be affected by the flaw.

A blog post by Cisco’s Talos security unit says the cyber-attacks are exploiting what Cisco officials are calling a “protocol misuse” situation in Cisco’s Smart Install Client, which is designed to enable the no-touch installation and deployment of new Cisco hardware, in particular Cisco switches.

Attackers have targeted a protocol issue with the Cisco Smart Install Client. If a user does not configure or turn off the Cisco Smart Install, it will hang out in the background waiting for commands on what to do.

For a brief review of Iran’s achievements in various fields of science and technology, check the book “Science and Technology in Iran: A Brief Review

Some reports indicate that some issues in the datacentres have created problems in using some of the popular sites, apps, and messengers in Iran as well many other countries. This has been caused by a disruption or potential attack on the communications infrastructure network in the past few hours.

Iran’s Communication and Information Technology Minister Mohammad Javad Azari-Jahromi has confirmed the attack on the country’s datacentres in a tweet.

The Iranian minister has also said that initial investigations indicate the settings of switching software have been attacked. A picture posted by Azari Jahromi shows the United States’ flag being in the background and a sentence that reads “don’t mess with our (US) elections.” Azari Jahromi has stressed that the attacks are not limited to Iran noting in another tweet that so far, more than 95 percent of switches have resumed their service.

Cisco has issued a warning and urged Smart Install client users to patch and securely configure the software.

Attackers are exploiting a “protocol misuse” issue in Cisco’s Smart Install Client to gain entry to critical infrastructure providers, according to researchers at Cisco’s Talos Intelligence group.

Cisco’s warning over the Smart Install client, a tool for rapidly deploying new switches, comes a week after it released a patch for a critical remote code execution flaw affecting the software.

On March 29, Cisco had warned that at least 8.5 million switches are open to attack.

Researchers have found that millions of Cisco network devices have been left vulnerable by an open TCP 4786 port.

Cisco has also seen a huge uptick in traffic to the TCP 4786 port that began around November 2017 and then spiked in April 2018.

According to Cisco, organizations can determine if a device is impacted by the Smart Install issues by running the command “show vstack config,” which will show if the Smart Install Client is active.

The easiest way to mitigate the issue is to run the command “no vstack” on the affected device. If this isn’t possible, the best option is to restrict access through an access control list for the interface.

Cisco in February 2017 issued an alert after discovering a rise in the number of internet scans for systems where the Smart Install Client was not turned off or configured with the property security controls. Without the right security controls, hackers can send new commands to the switches running Cisco’s IOS or IOS XE network operating system.

IFP Editorial Staff

The IFP Editorial Staff is composed of dozens of skilled journalists, news-writers, and analysts whose works are edited and published by experienced editors specialized in Iran News. The editor of each IFP Service is responsible for the report published by the Iran Front Page (IFP) news website, and can be contacted through the ways mentioned in the "IFP Editorial Staff" section.

Recent Posts

Iran denies meeting between UN envoy, Elon Musk

The Iranian Foreign Ministry has dismissed claims of a meeting between Elon Musk, a close…

18 minutes ago

Iran says plasma technology entered industrial phase

The head of the Atomic Energy Organization of Iran (AEOI), Mohammad Eslami, has announced that…

2 hours ago

Senior aide says conveyed Ayatollah Khamenei’s message of support for resistance to Syria, Lebanon

Ali Larijani, a senior advisor to Iran's Supreme Leader, has stated he conveyed Ayatollah Seyyed…

2 hours ago

Iran reaffirms commitment to pursuing legal action regarding assassination of General Soleimani

Iran's permanent mission to the United Nations has announced that Tehran is resolved to legally…

4 hours ago

EU has ‘convincing’ evidence of Chinese attack drone production for Russia: Report

The EU's top diplomat Josep Borrell has informed European nations of "convincing" evidence of Chinese…

4 hours ago

Iran and the US: Hope for de-escalation through new diplomacy?

In a surprising turn of events, unofficial reports have surfaced about a meeting between Elon…

7 hours ago