Cisco security flaw impacts critical SA infrastructure

Hanno Labuschagne

Journalist
Staff member
Joined
Sep 2, 2019
Messages
6,543
Reaction score
4,845
Cisco security flaw impacts critical SA infrastructure

At least 1,594 Cisco devices running the company’s IOS XE operating system in South Africa may be affected by a critical security flaw.

Devices running this software could be powering critical Internet and enterprise network infrastructure in South Africa and include enterprise switches, routers, and wireless controllers.
 
IT isn't fun another, more like it used to be 20 years ago, maybe even 10 years...
 
If you have HTTP exposed to the internet from a router then you deserve to the hacked.
Well yes, these days audits check for that specifically. But we know how it is in the world of corporates who cut to the bone and smaller businesses where a douchebag is in charge, rather spending money on a new Ferrari than decent network infrastructure.
 
Came to post this

(it's also https)

Management interfaces should not be on the Internet!
Correct for the management of any infrastructure - rather use a separate management plane that requires a auth using 2FA before you have access to it.

PS: All you Mikrotik guys take note. Your pants are all around your ankles.
 
Well yes, these days audits check for that specifically. But we know how it is in the world of corporates who cut to the bone and smaller businesses where a douchebag is in charge, rather spending money on a new Ferrari than decent network infrastructure.
Amazingly I concur on the small business owner who'd rather do a world tour than expend on better IT and IT support.

The problem is when the small business owners aren't really the tech type.
 
Well yes, these days audits check for that specifically. But we know how it is in the world of corporates who cut to the bone and smaller businesses where a douchebag is in charge, rather spending money on a new Ferrari than decent network infrastructure.
For the most part audits are a complete waste of time and just a tick in the box for management.

When auditors come you tell them what to check and provide evidence. Pointless. It gets worse and worse the larger the corporate - devices around that no one even knows about.
 
In my industry the audit is quite important, if not done, we are legally not allowed to trade
I agree it is important and a legal requirement for a lot of companies. But it's still a checkbox exercise. If a auditor signs off that everything is A ok you get that false sense of security that you are secure which is far from the truth. Only the things they've checked might be ok - what about the rest of the environment.
 
I agree it is important and a legal requirement for a lot of companies. But it's still a checkbox exercise. If a auditor signs off that everything is A ok you get that false sense of security that you are secure which is far from the truth. Only the things they've checked might be ok - what about the rest of the environment.
The pentesters are called in to check for other vulns. It's also part of the requirements.
 
I agree it is important and a legal requirement for a lot of companies. But it's still a checkbox exercise. If a auditor signs off that everything is A ok you get that false sense of security that you are secure which is far from the truth. Only the things they've checked might be ok - what about the rest of the environment.
Auditors are the bane of my existence. Being compliant with no findings is a really low bar these days.
 
Top
Sign up to the MyBroadband newsletter
X