4786-cisco-smart-install.md (3397B)
1 --- 2 title: "4786 - Cisco Smart Install" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/4786-cisco-smart-install.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4786-cisco-smart-install.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 4786 - Cisco Smart Install 14 15 ## Basic information 16 17 Cisco Smart Install is a legacy zero-touch deployment feature in which a director provides configuration files and software images to client switches. Communication between the director and clients uses TCP port **4786**.<sup>[[1]](#references)</sup> 18 19 **Default port:** 4786 20 21 ```text 22 PORT STATE SERVICE 23 4786/tcp open smart-install 24 ``` 25 26 ## CVE-2018-0171 27 28 CVE-2018-0171 is a critical Smart Install client vulnerability in affected Cisco IOS and IOS XE releases. An unauthenticated attacker can send a crafted message to TCP/4786 and trigger a buffer overflow, potentially causing a reload, arbitrary code execution, or a watchdog crash. Only vulnerable devices with Smart Install client functionality enabled are affected.<sup>[[2]](#references)</sup> 29 30 Cisco provides fixed releases. Where Smart Install is not needed, disable it with `no vstack`; where it must remain enabled, restrict TCP/4786 so that only the director can reach clients.<sup>[[2]](#references)[[3]](#references)</sup> 31 32 ## Smart Install Exploitation Tool 33 34 The [Smart Install Exploitation Tool (SIET)](https://github.com/frostbits-security/SIET) can test Smart Install exposure and retrieve a configuration from a vulnerable lab switch. Configuration files commonly contain sensitive topology and authentication data, so store and handle retrieved files as credentials.<sup>[[4]](#references)</sup> 35 36 In the following authorized lab example, `-g` requests the configuration and `-i` supplies the target address:<sup>[[4]](#references)</sup> 37 38 The original SIET walkthrough tested a physical Cisco Catalyst 2960. Virtual lab images do not necessarily implement Smart Install, so confirm that the chosen image exposes TCP/4786 before treating a failed virtual test as evidence that the technique does not work.<sup>[[4]](#references)</sup> 39 40 ```text 41 ~/opt/tools/SIET$ sudo python2 siet.py -g -i 10.10.100.10 42 ``` 43 44 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28773%29.png" alt=""><figcaption></figcaption></figure> 45 46 SIET stores the retrieved configuration under its `tftp/` directory. 47 48 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281116%29.png" alt=""><figcaption></figcaption></figure> 49 50 ## References 51 52 - [1] [Cisco Smart Install Configuration Guide](https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install.pdf) 53 - [2] [Cisco advisory - CVE-2018-0171 Smart Install remote code execution](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-smi2.html) 54 - [3] [Cisco - Action required to secure Smart Install](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180409-smi.html) 55 - [4] [SIET - Smart Install Exploitation Tool](https://github.com/frostbits-security/SIET)