meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 28th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 January 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cisco RV320/5 Vuln Exploited; Signed HTTP Exchanges; BGP Research Affects Routers

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 28, 2019 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich, and the time recording from Jacksonville, Florida.

0:14.1

We got two very recent vulnerabilities in Cisco RV 320 and RV 325 small business routers that are currently

0:24.6

widely being exploited.

0:26.6

A patch for these vulnerabilities was released just last week.

0:31.6

The first vulnerability CVE 2019 1652 is a command injection vulnerability in the router's web admin interface.

0:42.9

The vulnerability is only exploitable for an authenticated user, so this is why Cisco only

0:47.7

rated it as important, but first of all, the exploits that are going around now are going

0:53.6

for default credentials, Cisco slash Cisco, of course, the exports that are going around now are going for default credentials,

0:55.1

Cisco slash Cisco, of course. And then there is a second vulnerability, CVE 2019, 1653, so just the next

1:04.4

CVE number, so also released last week. And it's also rated high and also affects the web admin interface.

1:14.3

Now, the thing about this vulnerability is that allows the attacker to retrieve arbitrary URLs

1:21.6

without authentication, including the router's configuration file. Now, using this configuration file, an attacker then can obtain hash password.

1:33.3

The Etsy Shadow file can be downloaded.

1:36.3

And then, of course, they can brute force the password offline.

1:39.3

Again, if you have a weak password, you're sort of a sitting ducked there.

1:45.1

Yes, and of course, the Cisco slash Cisco password or account will immediately be cracked.

1:52.1

So definitely make sure that you expedite patching of these devices if you have an affected device.

1:58.3

And remember, the patch was released last week.

2:01.1

So if you didn't patch these routers within the last week,

2:04.8

you may be vulnerable.

2:06.3

In addition, definitely make sure that you use a strong password

2:09.5

that mitigates at least these sort of widespread exploits.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.