Cisco has released security updates to address a critical vulnerability in Cisco Umbrella Virtual Appliance (VA) that allowed unauthorized attackers to remotely obtain administrator credentials. The issue was discovered by Fraser Hess of Pinnacol Assurance in the SSH key authentication mechanism and was assigned the identifier CVE-2022-20773.

These Hyper-V and VMware ESXi-based virtual machines are used as conditional DNS proxies that encrypt, log, and authenticate DNS traffic through the Cisco Umbrella cloud solution, which is used by more than 24,000 companies to protect against malware, phishing, and ransomware. The vulnerability affects Cisco Umbrella VA software versions prior to 3.3.2.

According to Cisco, “the issue is caused by the presence of a static SSH host. An attacker could exploit this vulnerability through a man-in-the-middle attack on the SSH connection to Umbrella VA. Successful exploitation allows the attacker to obtain administrator credentials, change settings, or reboot the virtual device.”

Fortunately, the SSH service on Umbrella virtual machines is disabled by default, which reduces the risks. To check the status of SSH, connect to the hypervisor console, press CTRL+B to enter configuration mode, and run the config VA show command. If SSH is enabled, the line “SSH access: enabled” will appear at the end of the output.

At the time of publication, there are no ways to mitigate the vulnerability without updating the software, so Cisco recommends that all customers install the fixed version. The Cisco PSIRT team also noted that there is no public exploit or code examples for this vulnerability, and there is no evidence of active exploitation.

Cisco previously addressed a similar issue, CVE-2021-40119, in the SSH key authentication method in Cisco Policy Suite, which allowed unauthorized users to remotely log in with root privileges. On the same day, another critical vulnerability in the Telnet service of Cisco Catalyst PON Series ONT switches (CVE-2021-34795) was fixed, allowing attackers to log in remotely using a debug account and a default password.