Menu
Cisco warns customers about attacks installing rogue firmware on networking gear

Cisco warns customers about attacks installing rogue firmware on networking gear

Compromised administrative credentials were used to flash malicious boot firmware on Cisco IOS devices

Installing rogue firmware on embedded devices has long been a concern for security researchers, and it seems that such attacks have started to gain ground with hackers.

In an advisory Tuesday, Cisco Systems warned customers that it is aware of a limited number of cases where attackers have replaced the boot firmware on devices running its IOS operating system. IOS runs on most Cisco routers and switches and provides a complex set of networking tools and features.

Attackers used valid administrative credentials in order to replace the ROMMON image on IOS devices, Cisco said.

ROMMON, or ROM Monitor, is the low-level firmware responsible for initializing the hardware and booting up IOS. This means the attack is the equivalent of replacing the BIOS or UEFI (Unified Extensible Firmware Interface) on PCs with a malicious version.

"No product vulnerability is leveraged in this attack, and the attacker requires valid administrative credentials or physical access to the system to be successful," Cisco said in its advisory. "The ability to install an upgraded ROMMON image on IOS devices is a standard, documented feature that administrators use to manage their networks."

It's not clear how the attackers obtained the administrative credentials used in the ROMMON compromises seen by Cisco, but it should serve as a warning for companies with IOS equipment that network administrators are a target.

For attackers, the benefit of installing a malicious ROMMON image on a device is that it makes compromises persistent, as typical IOS infections don't survive across reboots.

Researchers have long highlighted the risk of attackers flashing rogue firmware on embedded devices in the absence of protections like encrypted and digitally signed updates. However, real-world attacks using this method have been rare until now.

Cisco first introduced a software digital signature verification feature in IOS Software Release 15.0(1)M for the Cisco 1900, 2900 and 3900 Series routers, as well as in IOS XE Release 3.1.0SG for Cisco Catalyst 4500 E-Series Switches.

The prevent, detect and remedy compromises of Cisco IOS devices, the company's product security incident response team advises customers to follow recommendations outlined in three documents: Cisco IOS Software Integrity Assurance, Cisco Guide to Harden IOS Devices and Telemetry-Based Infrastructure Device Integrity Monitoring.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags NetworkingCisco Systems

Featured

Slideshows

How MSPs can capitalise on integrating AI into existing services

How MSPs can capitalise on integrating AI into existing services

​Given the pace of change, scale of digitalisation and evolution of generative AI, partners must get ahead of the trends to capture the best use of innovative AI solutions to develop new service opportunities. For MSPs, integrating AI capabilities into existing service portfolios can unlock enhancements in key areas including managed hosting, cloud computing and data centre management. This exclusive Reseller News roundtable in association with rhipe, a Crayon company and VMware, focused on how partners can integrate generative AI solutions into existing service offerings and unlocking new revenue streams.

How MSPs can capitalise on integrating AI into existing services
Access4 holds inaugural A/NZ Annual Conference

Access4 holds inaugural A/NZ Annual Conference

​Access4 held its inaugural Annual Conference in Port Douglass, Queensland, for Australia and New Zealand from 9-11 October, hosting partners from across the region with presentations on Access4 product updates, its 2023 Partner of the Year awards and more.

Access4 holds inaugural A/NZ Annual Conference
Show Comments