Cisco Bundles Fixes for Multiple IOS XR Vulnerabilities
Cisco has released a bundle of patches to address multiple vulnerabilities in its IOS XR Linux-based network operating system, including some that are critical. The company's software engineering team flagged the flaws during internal testing, which could allow attackers to perform remote code execution and gain root access on routers.
The vulnerabilities, rated between 9.8 and 8.2 in severity, include issues with lifetime resource control, incorrect network usage calculations, and improper checks or handling of exceptional conditions. While Cisco emphasizes that the flaws are not yet known to be actively exploited, experts warn that attackers may try to exploit them.
David Shipley of Beauceron Security noted that both remote code execution and root router access are in the Salt Typhoon playbook, adding that worst-case scenarios could result in widespread network disruption and outages. Shipley also commented on the use of AI in finding vulnerabilities, stating that it has become an 'AI-against-AI race'.
Erik Avakian, a technical counselor at Info-Tech Research Group, advised prioritizing patching based on exposure and criticality, recommending that internet-facing and core routing systems be patched first. He also emphasized the importance of zero-trust principles, including restricting administrative access and applying segmentation and access control lists (ACLs).