Cisco CloudCenter Orchestrator Flaw Exploited in Attacks
Summary
The security hole, discovered during the resolution of support cases, exists due to a misconfiguration that makes the Docker Engine management port reachable from the outside. An attacker can exploit this weakness to load Docker containers with arbitrary privileges, including root, on the affected CCO system. A CCO installation is vulnerable if TCP port 2375 is open and bound to the 0.0.0.0 local IP address, which is the default configuration. Cisco’s Product Security Incident Response Team (PSIRT) said it was aware of a limited number of cases where this vulnerability had been exploited publicly. The company recently learned that the NSA-linked actor known as the Equation Group had several exploits targeting its products, including ones relying on previously unknown vulnerabilities.