A simple command allows the CIA to commandeer 318 models of Cisco switches

Credit: arstechnica.com

Cisco Systems said that more than 300 models of switches it sells contain a critical vulnerability that allows the CIA to use a simple command to remotely execute malicious code that takes full control of the devices. There currently is no fix.

Cisco researchers said they discovered the vulnerability as they analyzed a cache of documents that are believed to have been stolen from the CIA and published by WikiLeaks two weeks ago. The flaw, found in at least 318 switches, allows remote attackers to execute code that runs with elevated privileges, Cisco warned in an advisory published Friday. The bug resides in the Cisco Cluster Management Protocol (CMP), which uses the telnet protocol to deliver signals and commands on internal networks. It stems from a failure to restrict telnet options to local communications and the incorrect processing of malformed CMP-only telnet options.

"An attacker could exploit this vulnerability by sending malformed CMP-specific telnet options while establishing a telnet session with an affected Cisco device configured to accept telnet connections," the advisory stated. "An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device."

Top Stories

Amazon Chime team responds to trademark suit, claims it wasn’t aware of competing Chime service

An Amazon Web Services employee claims the company had never heard of CafeX Communications and its competing Chime service when it decided to christen its new set of conferencing and collaboration tools Amazon Chime. Soon after AWS announced the new Amazon Chime service, New York-based CafeX slapped Amazon with a federal trademark lawsuit. In court documents filed Wednesday, AWS Product Manager Jennie Tietema, who was involved in naming Amazon Chime, disputes claims made by CafeX that Amazon knew about its Chime product and deliberately ripped off the name. “The first time I recall ever hearing of CafeX was when the litigation was filed and I… Read More
  • 2 days ago
  • 11

Salesforce CEO Marc Benioff talks ‘crisis of trust’ in the world and jobs in the era of AI

Artificial intelligence is going to transform and impact many jobs, and it is up to the companies building the technology and government agencies regulating it to make sure it is a force for good, Salesforce CEO Marc Benioff said during a conversation with IBM CEO Ginni Rometty during the IBM InterConnect conference in Las Vegas Tuesday. The two companies earlier this month announced a surprise AI partnership. The companies will combine aspects of their respective AI technologies — IBM’s Watson and Salesforce’s Einstein — in a new bid to win customers in the emerging world of cloud-based artificial intelligence. For example, they say, Watson… Read More
  • 3 days ago
  • 11

Amazon and DHL reportedly team up for Prime Air and Amazon Fresh deliveries

Amazon is reportedly partnering with the German-based DHL delivery service for its Prime Air transport operation in Kentucky as well as for Amazon Fresh food deliveries in Germany. The Lane Report says Amazon will begin processing shipments at DHL’s facility at Cincinnati-Northern Kentucky International Airport in May. The arrangement would give Amazon a head start on its $1.5 billion plan to use the airport as a major shipping hub for its Prime Air fleet. DHL would use the facility at night for its own operations, as usual, but let Amazon use it during the day, sources told The Lane Report.… Read More
  • 2 days ago
  • 10

Boy meets artificial girl: My son got an Echo Dot, and here’s what he’s saying to Amazon’s Alexa

In my 10 years as a parent, I’ve served as the authority on a number of subjects, ranging from when one might expect a cut to stop bleeding to why there are no more dinosaurs. But there’s a new voice in my house fielding questions from my curious kid, and we’re all learning what it’s like to live with one another. Amazon’s Alexa showed up inside an Echo Dot last week, courtesy of grandparents on the other side of the country looking to wow a Seattle kid on his birthday. From the moment she was powered on and linked to various devices around… Read More
  • 4 days ago
  • 10

Washington state and Seattle consider requiring companies to offer paid family and medical leave

The City of Seattle and Washington state are considering policies that would require businesses to offer paid family and medical leave — both of which would be funded through payroll fees. A representative from Olympia met with the Seattle City Council Wednesday to discuss the separate but related initiatives. The state’s divided legislative branches face an uphill battle finding a paid leave compromise, but far-left Seattle seems poised to implement a program over the next few years. That means businesses in Seattle could be required to offer six months of paid time off to care for new children or sick family members,… Read More
  • 1 day ago
  • 9
exclusivetailor - Easy Branches
farawayyachtingcharters - Easy Branches
louiscollections - Easy Branches
botoxfillerveintheraphyinphuket - Easy Branches

Latest in Technology

Mobile ad developer claims in lawsuit it was cut out of Amazon smartphone deal by partner

An expansion of Amazon’s discounted smartphone program for Prime members is at the center of a lawsuit filed in Los Angeles last week. Pay Per Swipe, a Los Angeles-based mobile advertising company that builds apps to put ads on smartphone lock screens, sued TCT Mobile, an entity that shares an Irvine, Calif., address with phone maker Alcatel, for breach of contract and unfair business practices, among other charges. Pay Per Swipe alleges that TCT broke a non-disclosure agreement and used confidential information about lock screen ad products the two firms worked on together for its own gain. TCT allegedly used that information… Read More
  • 35 minutes ago

GeekWire Deals: Master design industry favorites Adobe Photoshop, Illustrator, and Premiere Pro

From advertising to products, the world is run by design. That’s why superior work is done with quality software like Adobe Photoshop, Illustrator, and Premiere Pro. Any skill set is deeply enhanced by fluency in these programs, so let today’s GeekWire Deals offer get you there. Enroll in your Adobe education with the Adobe CC Essentials Training Bundle. Manipulate photography and create new imagery to conjure up remarkable graphics in Adobe Photoshop. Become familiar with vector illustration to design for web and many modern platforms in Adobe Illustrator. Make it dynamic with visually stunning video editing in Adobe Premiere Pro.… Read More
  • 35 minutes ago

On World TB Day, meet who are taking on the world’s deadliest pathogen

To many people, tuberculosis is a disease confined to places far away or to times long gone by. But the distance between us and this deadly pathogen is far smaller than we may imagine: in just the last six months, there have been two TB scares in the Seattle area, and one out of every three people in the world carries the TB bacteria. TB is one of the oldest and smartest known pathogens, and despite huge success in decreasing TB deaths in the past few decades, it still kills 1.5 million people every year. “It’s co-evolved with humans throughout all… Read More
  • 2 hours ago

Pop culture powerhouse Funko to open giant flagship store in new Everett headquarters building

Funko, makers of pop culture figurines and much more, is growing so rapidly that it needs more space for its headquarters in Everett, Wash. With its move to a historic building downtown, the company will also be opening a giant flagship retail location this summer. KING 5 reported Friday that the 19-year-old company plans a store with 17,000 square feet of retail space which will also serve as a worldwide tourist destination for Funko products. The location at 2802 Wetmore Ave. is set to open Aug. 18. The company holds hundreds of licenses for tens of thousands of characters across such franchises as Star… Read More
  • 2 hours ago

Uber GM says service may leave Seattle if landmark union law is implemented

Uber’s popular ride-hailing service may leave Seattle if a first-of-its-kind law allowing drivers to collectively bargain is implemented as planned. So said Brooke Steger, Uber’s Pacific Northwest general manager, at a Public Relations Society of America event in Seattle that focused on communications lessons from the company. “We’re unsure of the future of Uber in Seattle,” she said. “We don’t know if we will be able to continue to operate here and so it’s very important to us, obviously. It also is important to us nationally because I think us leaving a big city like Seattle, one of our first cities, has some pretty… Read More
  • 2 hours ago

Azure Service Fabric takes first tentative steps toward open source

Service Fabric started as an internal platform for Azure SQL, Cortana, and other services.
  • 2 hours ago

Elon Musk posts a sneak peek of the first drive for a Tesla Model 3 electric car

Tesla’s billionaire CEO, Elon Musk, is showing off a video of the company’s more affordable Model 3 electric car – but he’s also touting Tesla’s pricier models. A clip that shows a black release candidate version of the Model 3 zipping down the street popped up this morning on Musk’s Twitter and Instagram feeds, and quickly picked up tens of thousands of views, plus thousands of shares: First drive of a release candidate version of Model 3 pic.twitter.com/zcs6j1YRa4 — Elon Musk (@elonmusk) March 24, 2017 Tesla is counting on the Model 3 to bring electric cars to the masses: It’s thought… Read More
  • 3 hours ago

How ISPs can sell your Web history—and how to stop them

How the Senate's vote to kill privacy rules affects you.
  • 3 hours ago

‘Life’ horror movie sparks reality check on procedures for studying Mars samples

Spoiler Alert! This article doesn’t reveal any major plot twists, but wait to read it if you’re trying to stay totally in the dark about the plot of the movie “Life.” Let sleeping Martians lie, particularly if they have a strong grip: That’s one of the lessons you could take away from “Life,” the first monster movie set on the International Space Station. Previously: ‘Life’ draws upon real-life biology and worst-case space scenarios The movie – which opens today and stars Jake Gyllenhaal, Rebecca Ferguson and Ryan Reynolds – blends the gory horror of “Alien” with the harrowing suspense of “Gravity.” It’s a… Read More
  • 5 hours ago

Google reportedly removing SMS texting from Hangouts on May 22

But Google Voice users won't be affected as much.
  • 5 hours ago

Alibaba gets serious in Southeast Asia in preparation for battle with Amazon

 Done betting, Alibaba is getting down to work in Southeast Asia as it bids to lead the region’s promising e-commerce space and maximize its early mover advantage over Amazon. Alibaba became the first major international player to enter Southeast Asia, a region with more than 600 million cumulative consumers, when it bought a majority stake in Lazada, the Rocket Internet-backed… Read More
  • 6 hours ago

Socedo raises another $1M for lead generation platform that analyzes social media activity

Socedo is raising more cash to build out its platform that helps companies target sales leads from social media activity. The Seattle startup today announced a $1 million investment from TechStars Ventures, Vulcan Capital, Divergent Ventures and angel investors. Total funding in the 4-year-old company is $2.5 million. Socedo, a 2013 graduate of the Microsoft Windows Azure accelerator, helps clients like Microsoft, Lenovo, Google, Extreme Networks, and more than 170 other customers streamline the process of finding sales leads on social media. The company’s software combines real-time social media activity monitoring with profile data from sources like Twitter and LinkedIn. That information is then synced with a… Read More
  • 7 hours ago