IKEv1 Information Disclosure Vulnerability in Multiple Cisco Products
tools.cisco.com
tools.cisco.com
Fixing it would've at least prevented exploitation, but there is value in knowledge of who else has this exploit and who they're trying to attack.
I'm almost glad we don't since defensive capabilities are the kind of thing you'd rather not disclose to your adversary until you truly need to leverage them, but at the same time, with all the leaks, it's as if the NSA just runs offensive operations and reactive analysis/reconnaissance.
If different teams finding the same bugs was common, then someone else probably would have found this one sometime in the last 14 years and reported it to Cisco such that it was actually closed. Therefore, finding overlapping bugs is rare -> NSA should stockpile bugs.
(We probably should have a separate agency in charge of attempting to make things more secure, perhaps by finding and reporting bugs like this)
So basically heartbleed for Cisco VPN's.
Call me crazy, but could one not work around this by ... I don't know, disabling IKEv1?
IKE 1 was seemingly purposely complicated.
Not saying it's not reasonable for the NSA to have exploited (they probably did), but unless we have proof, the headline is a bit clickbait-ish.
⌘F
I don't see any reference to this exploit being used 14 years ago though, although the code being exploited is that old.
> The exploit of this vulnerability was publicly disclosed by the alleged Shadow Brokers group for Cisco PIX.