daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

4786-cisco-smart-install.md (3397B)


      1 ---
      2 title: "4786 - Cisco Smart Install"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/4786-cisco-smart-install.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/4786-cisco-smart-install.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 4786 - Cisco Smart Install
     14 
     15 ## Basic information
     16 
     17 Cisco Smart Install is a legacy zero-touch deployment feature in which a director provides configuration files and software images to client switches. Communication between the director and clients uses TCP port **4786**.<sup>[[1]](#references)</sup>
     18 
     19 **Default port:** 4786
     20 
     21 ```text
     22 PORT      STATE  SERVICE
     23 4786/tcp  open   smart-install
     24 ```
     25 
     26 ## CVE-2018-0171
     27 
     28 CVE-2018-0171 is a critical Smart Install client vulnerability in affected Cisco IOS and IOS XE releases. An unauthenticated attacker can send a crafted message to TCP/4786 and trigger a buffer overflow, potentially causing a reload, arbitrary code execution, or a watchdog crash. Only vulnerable devices with Smart Install client functionality enabled are affected.<sup>[[2]](#references)</sup>
     29 
     30 Cisco provides fixed releases. Where Smart Install is not needed, disable it with `no vstack`; where it must remain enabled, restrict TCP/4786 so that only the director can reach clients.<sup>[[2]](#references)[[3]](#references)</sup>
     31 
     32 ## Smart Install Exploitation Tool
     33 
     34 The [Smart Install Exploitation Tool (SIET)](https://github.com/frostbits-security/SIET) can test Smart Install exposure and retrieve a configuration from a vulnerable lab switch. Configuration files commonly contain sensitive topology and authentication data, so store and handle retrieved files as credentials.<sup>[[4]](#references)</sup>
     35 
     36 In the following authorized lab example, `-g` requests the configuration and `-i` supplies the target address:<sup>[[4]](#references)</sup>
     37 
     38 The original SIET walkthrough tested a physical Cisco Catalyst 2960. Virtual lab images do not necessarily implement Smart Install, so confirm that the chosen image exposes TCP/4786 before treating a failed virtual test as evidence that the technique does not work.<sup>[[4]](#references)</sup>
     39 
     40 ```text
     41 ~/opt/tools/SIET$ sudo python2 siet.py -g -i 10.10.100.10
     42 ```
     43 
     44 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28773%29.png" alt=""><figcaption></figcaption></figure>
     45 
     46 SIET stores the retrieved configuration under its `tftp/` directory.
     47 
     48 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281116%29.png" alt=""><figcaption></figcaption></figure>
     49 
     50 ## References
     51 
     52 - [1] [Cisco Smart Install Configuration Guide](https://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install.pdf)
     53 - [2] [Cisco advisory - CVE-2018-0171 Smart Install remote code execution](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-smi2.html)
     54 - [3] [Cisco - Action required to secure Smart Install](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180409-smi.html)
     55 - [4] [SIET - Smart Install Exploitation Tool](https://github.com/frostbits-security/SIET)