I just found it amusing that Cisco's wording is, it's bad, but it's designed to 
work that way.

Insecure by Design.

Sigh...

As a minor point of comparison, we do zero touch deployment for our VoIP 
handsets, but we basically scan the mac address of the pickingslip/side of box, 
then dump that into our provisioning system, which is advertised to the phones 
via DHCP option. This at least requires to be in the L2 broadcast domain to 
poke these.

This a routable L3 auto-configure, which strikes me personally, as incredibly 
stupid. But smarter heads than mine must know better.

-M

From: Michael Junek [mailto:[email protected]]
Sent: Wednesday, 9 May 2018 2:27 PM
To: Michael J. Carmody <[email protected]>; [email protected]
Subject: Re: Bouncing Cisco Equipment and "Smart Install"


Hi Michael,



When I recently deployed a few 9300's in our DC, this feature was disabled 
before bringing in external connectivity because one of our engineers here was 
aware of this vulnerability and removed it.



It's enabled out of the box because the idea is that it's for zero-touch 
initial provisioning of the switch. The above engineer was working on a large 
infrastructure project for a govt department, which involved deploying 
approximately 600x 3850 switches. These were set up in a central system and 
when powered on, the configs were delivered, rather than having to console into 
every switch and deploy the configuration.



Michael







________________________________
From: AusNOG 
<[email protected]<mailto:[email protected]>> on 
behalf of Michael J. Carmody <[email protected]<mailto:[email protected]>>
Sent: Wednesday, 9 May 2018 14:21
To: [email protected]<mailto:[email protected]>
Subject: [AusNOG] Bouncing Cisco Equipment and "Smart Install"

Hey All,

Just a feeler to see if anyone else is seeing this.

We have some Cisco switches we use as Layer 2/3 NTU's to talk to client 
equipment on the far ends of fibre links.

As of yesterday morning, all of these switches started a roughly 1-2 hour 
reboot outage.

All smartnet'ed, running latest recommended stable from cisco, and nothing in 
the logs other than a hard reset just occurred.

We have been additionally hardening the exposure of various interfaces (attacks 
were captured coming from resi ISP looking .mx domains), and it appears the one 
that has stopped the rot is disabling the "Smart Install" feature with a "no 
vstack" command, reload config from out config store and back to work...

TBH I didn't even know this protocol existed... a non-authenticated, on by 
default protocol that allows you to configure and image deploy on network 
equipment.

Like, its our own fault, but what the hell is this doing on by default?

Anyone else with Cisco or "Smart Install" equipment seeing an uptick in 
scanning/poking activity?

-Michael Carmody

(Ref: 
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170214-smi
 )
_______________________________________________
AusNOG mailing list
[email protected]
http://lists.ausnog.net/mailman/listinfo/ausnog

Reply via email to