Thrangrycat flaw lets attackers plant persistent backdoors on Cisco gear

General News

Summary

Named Thrangrycat, the vulnerability impacts the Trust Anchor module (TAm), a proprietary hardware security chip part of Cisco gear since 2013. The TAm runs from an external, hardware-isolated component that cryptographically verifies that the bootloader that loads and executes on Cisco gear is authentic. However, if an attacker chains a security flaw that lets them get access to Cisco gear as root, then this vulnerability comes into play and becomes a big problem for device owners. This means that by combining Thrangrycat (CVE-2019-1649) with this remote code execution flaw (CVE-2019-1862), an attacker located anywhere on the internet can take over devices, gain root access, and then disable the TAm boot process verification, and even prevent future TAm security updates from reaching devices. This, in turn, allows attackers to modify Cisco firmware and plant persistent backdoors on targeted devices.

Classifications

industries
No industries detected
applications
General BI

AskAI Classifications

Labels
SaaS Enterprise Software Collaboration Software

Linked Companies

Cisco
$1B+