Security News > 2020 > May > Cisco hacked: Six backend servers used by customer VIRL-PE deployments compromised via SaltStack
Six Cisco-operated servers were hacked via SaltStack security vulnerabilities, the networking giant revealed this week.
The compromised systems act as the salt-master servers for releases 1.2 and 1.3 of Cisco's Virtual Internet Routing Lab Personal Edition product, and customer installations connect to these Cisco-maintained backend boxes.
Cisco patched the six VIRL-PE salt-master boxes - us-1.virl.
In the same advisory, Cisco said it has patched the two critical SaltStack vulnerabilities - CVE-2020-11651 and CVE-2020-11652 - in VIRL-PE and Cisco Modeling Labs Corporate Edition.
Cisco acquired internet and network monitoring biz ThousandEyes in a deal thought to total $1bn. The San Francisco upstart will be merged with Cisco's new Networking Services business unit.
News URL
https://go.theregister.com/feed/www.theregister.com/2020/05/31/cisco_security_roundup/
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-04-30 | CVE-2020-11651 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. | 9.8 |
2020-04-30 | CVE-2020-11652 | Path Traversal vulnerability in multiple products An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. | 6.5 |