[179425] in North American Network Operators' Group
Re: Cisco Routers Vulnerability
daemon@ATHENA.MIT.EDU (Nick Hilliard)
Mon Apr 13 17:45:07 2015
X-Original-To: nanog@nanog.org
X-Envelope-To: nanog@nanog.org
Date: Mon, 13 Apr 2015 23:44:57 +0200
From: Nick Hilliard <nick@foobar.org>
To: Rashed Alwarrag <rali.ahmed@gmail.com>, nanog@nanog.org
In-Reply-To: <CAEwtr5qTMaG2Nbnnj7Q-pBOaWc-cPoiZGsKjENDUDqCvr4_bZA@mail.gmail.com>
Errors-To: nanog-bounces@nanog.org
On 13/04/2015 23:29, Rashed Alwarrag wrote:
> Today we have a lot of customers report that their Cisco routers got a root
> access and the IOS got erased , is there any known vulnerability in cisco
> products thats they report in their Security alerts about this recently ?
> is there any one face the same issue ?
"show tech-support" might give you a list of the last commands issued on
the devices. It's more likely to be a password compromise than a remote vuln.
Nick