iTnews Asia
  • Home
  • News
  • Security

Cisco Catalyst 9300 supply chain vulnerability patched

Cisco Catalyst 9300 supply chain vulnerability patched

Attacker with physical access could install "persistent code".

By Richard Chirgwin on Mar 23, 2023 12:09PM

Cisco has revealed a high-rated vulnerability in its Catalyst 9300 switch software that could allow persistent code to be installed by an attacker at boot time.

The bug, detailed here, requires “level-15 privileges”, or “an unauthenticated attacker with physical access” to be exploited.

That means a bad actor in the supply chain – for example, compromised reseller staff – could “execute persistent code at boot time and break the chain of trust”.

“This vulnerability is due to errors that occur when retrieving the public release key that is used for image signature verification," the advisory stated.

The switches are vulnerable if they’re running IOS XE software using an IOS XE ROM Monitor earlier than Release 17.3.7r, Release 17.6.5r, or Release 17.8.1r.

The bug was one of nine high-rated and nine medium-rated vulnerabilities disclosed today, including six related to the company’s IOS and IOS XE software.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
catalyst 9300 cisco security vulnerability

Related Articles

  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
  • Beware the rise of ‘vishing’ as a cyber threat in APAC
  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Five tips a CIO or CSO should know to stop employee-driven IP theft

Five tips a CIO or CSO should know to stop employee-driven IP theft

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

Beware the rise of ‘vishing’ as a cyber threat in APAC

Beware the rise of ‘vishing’ as a cyber threat in APAC

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.