In multiple models of both Aruba and Avaya switches, Armis has detected five vulnerabilities relating to the implementation of TLS communications.
Using these vulnerabilities, there is a possibility that remote access could be gained to networks of enterprise companies, and confidential information could be stolen.
Following the disclosure of TLStorm last March, these findings serve as a follow-up. An attacker may be able to take control and, worse, damage the appliances via three critical flaws found in APC Smart-UPS devices.
NanoSSL, a popular TLS library offered by Mocana, was used inappropriately as the source of these vulnerabilities.
The security analysts at Armis discovered that several devices using Mocana NanoSSL are being sabotaged by the same problem even though they may come from two distinct switch vendors, but they got affected by the same misuse of NanoSSL.
Both Aruba and Avaya Networking have switches that are vulnerable to RCE flaws and over the network, all these RCE flaws can be exploited by the threat actors. And apart from this, the new set of flaws, dubbed TLStorm 2.0.
The following devices are among the affected ones:-
The vulnerabilities were due to what Armis called an “edge case,” an inability to follow the guidelines regarding the NanoSSL library, which could have led to RCE (Remote Code Execution).
And here we have mentioned all the security flaws detected by the security analysts:-
It is important to remember that the exploitation of RCE vulnerabilities can lead to many things, such as:-
Moreover, the security flaws found in Avaya switches are not limited to being exploitable through unauthenticated packets of network data, meaning that they can be exploited without the involvement of the user.
In short, the security flaws found in Avaya switches are zero-day flaws. It is highly recommended that organizations that employ devices from Avaya and Aruba are patched as soon as possible so that they remain protected.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…