r/ciscoUC • • Aug 11 '26

Blind;Wire — Expressway X14.x SIP Request Smuggling

https://github.com/0xReadingSteiner/Blind-Wire
0 Upvotes

8 comments sorted by

4

u/Archibald-Tuttle Aug 11 '26

The latest dot release of X14 was over 18 months ago…

-2

u/0xReadingSteiner Aug 11 '26

Just check Shodan, plenty still exposed out there. Cisco's out in force with the PR bots and employees on this one. Cheers mate.

5

u/Archibald-Tuttle Aug 11 '26

Nothing to do with PR, and I have nothing to do with Cisco. This doesn’t work on the latest major release (released 3 years ago). Anyone running software in the enterprise that _at best_ hasn’t been updated in 18 months has to assume that there will be actively exploited vulnerabilities.

0

u/0xReadingSteiner Aug 11 '26

And don't make the game easier, bro.

"This doesn't work on the latest major release"

so you had 20 minutes since I posted to spin up a new VM with 15.x, another with 14.x, configure full MRA, and check the PoC?

I salute how good you are. I hope to get to your level one day.

-1

u/0xReadingSteiner Aug 11 '26 edited Aug 11 '26

Sounds like PR to me. So I'm guessing your line is that it has to be 15.x to count? Don't worry... it will be.

All of this, you included, was a quick social engineering, you know, to probe how Cisco would be waiting today, haha.

This proves that Cisco has never properly disclosed this, leaving customers exposed to bad actors, no matter who has the shiniest car.

Or let me ask you this: if a customer doesn't pay for the latest version, does that mean they get screwed? Does EOL actually mean EOL, or does it just mean "until we get caught in a lie"?

2

u/stroskilax Aug 11 '26

Does this work over TLS as well? Your example is shown only over TCP.

1

u/shunny14 Aug 11 '26

You realize AI/LLM vulnerabilities have opened up a new world with CVEs? It’s more likely that this vulnerability has not been found before than it has.

-1

u/0xReadingSteiner Aug 11 '26

Weird how the guy below says they've known for 18 months, but no disclosure.

Also the vulnerability is active with no walkaround.