Submission + - Cisco discloses security breach that impacted VIRL-PE infrastructure (zdnet.com)
An anonymous reader writes: Cisco has disclosed today a security breach that impacted a small part of its backend infrastructure. In a security alert published today, Cisco said that hackers used a vulnerability in the SaltStack software package, which Cisco bundles with some products, to gain access to six servers. The six servers provide the backend infrastructure for VIRL-PE (Internet Routing Lab Personal Edition), a Cisco service that lets users model and create virtual network architectures to test network setups before deploying equipment in real situations.
The intrusion was detected and remediated on May 7, but today Cisco has issued patches for on-premise VIRL-PE and CML products. The hack took place because Cisco gear was bundling SaltStack, the software that was also used to breach servers at LineageOS, Ghost, Xen Orchestra, and Digicert.
The intrusion was detected and remediated on May 7, but today Cisco has issued patches for on-premise VIRL-PE and CML products. The hack took place because Cisco gear was bundling SaltStack, the software that was also used to breach servers at LineageOS, Ghost, Xen Orchestra, and Digicert.