HTTP: Cisco Security Manager Multiple Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against Cisco Security Manager. A successful attack can lead to arbitrary code execution.

Extended Description

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit these vulnerabilities by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of NT AUTHORITY\SYSTEM on the Windows target host. Cisco has not released software updates that address these vulnerabilities.

Affected Products

Cisco security_manager

Short Name
HTTP:CISCO:SECMGR-MUL-INSECDES
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-27131 Cisco Deserialization Insecure Manager Multiple Security
Release Date
01/07/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3344
False Positive
Unknown
Vendors

Cisco

CVSS Score

10.0

Found a potential security threat?