Skip to content

Build1 publisher2 min readPublished

Cisco's remediation path for a suspect virtual email gateway starts with a new VM

For virtual appliances where exploitation is suspected, Cisco's advisory lists five actions before the box can be trusted again, one of which is installing fixed software. Owners of physical appliances are told to call TAC.

The Engineer · Build desk

Illustration accompanying Cisco's remediation path for a suspect virtual email gateway starts with a new VM

What happened

  • Cisco's advisory for a SQL injection vulnerability in Secure Email Gateway tells customers who suspect exploitation of a virtual appliance to deploy a new virtual machine on a fixed release and rebuild the product configuration.
  • The same sequence tells operators to renew credentials and any cryptographic materials installed on the appliance, then continue monitoring the system for anomalous behaviour.
  • Cisco says it found indicators of possible compromise on some Secure Email Cloud devices, contacted those owners directly, and has deployed the mitigations that sit within its own management.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Incident response has to be staffed before the maintenance window opens, because the appliance cannot be preserved and redeployed at the same time.
  • decision One word splits the affected population: sites that do not suspect exploitation upgrade in place, while the rest reconstruct a mail gateway configuration by hand.
  • exposure Rotation reaches systems that were never in the patch's scope, since anything the gateway used to authenticate elsewhere has to be reissued on the far side.
  • cost Owners of physical appliances have to open a TAC engagement and enable remote access into a device they already suspect.

Cisco marks one step in the virtual-appliance path Important, and it is the first one. Record forensics information before continuing, the advisory says, because "Deploying a new instance will destroy the configurations and logs" [3]. The appliance cannot be preserved and redeployed at the same time, and Cisco puts the forensics first.

Count the actions in that branch. There are five: preserve forensics, deploy a new virtual machine running one of the fixed software releases, and rebuild the product configuration. Then renew credentials and any cryptographic materials installed on the appliance, and keep monitoring for anomalous behaviour [2][3][4]. One of the five installs fixed software. The other four fall to the operator [19].

The credential step is the one that leaves the appliance. Cisco says to renew credentials and any cryptographic materials that are installed on the appliance [4], and the guidance does not enumerate which ones qualify. Whatever the gateway held in order to authenticate to a directory, a relay or a management host has to be reissued at the other end as well.

Physical appliances get different instructions. Cisco asks customers who suspect exploitation of a physical appliance to contact the Technical Assistance Center, and to ensure remote access is enabled on the affected appliances so the investigation can be expedited [7]. The general hardening list in the same document says to prevent access from the internet to the appliance. Where access is required, restrict it to known, trusted hosts on ports and protocols documented in the user guides [10]. So the same document asks operators to enable remote access on a box they suspect is already being accessed remotely.

For Cisco Secure Email Cloud, Cisco says it ran a threat intelligence investigation and contacted the owners of devices where indicators of possible compromise were identified. It has already deployed the mitigations that are within Cisco's management [8]. Those contacted customers are still told to renew credentials and any cryptographic materials installed on the appliance, when possible [9].

Nine of the ten general hardening items are configuration and access control; the tenth is upgrading to the latest AsyncOS release [20]. One of the nine decides which branch an operator ends up in: logging sent to an external server, kept long enough that post-event investigations can be performed with sufficient log data [12]. Cisco's upgrade-only option applies when exploitation is not suspected [6]. If the appliance is the only place its logs ever lived, that condition is a claim about visibility. I would not make it.

What to watch

  • A revision to the advisory that names which credential and certificate types on the appliance require renewal.
  • Cisco identifying indicators of possible compromise on further Secure Email Cloud devices and contacting a wider set of customers.
  • Whether the physical-appliance guidance stays a TAC engagement or moves toward the rebuild sequence written for virtual devices.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories