Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

VPNs at risk from security glitch

Marguerite Reardon CNET News

Published: 15 Nov 2005 10:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in a key Internet security protocol used by major networking products could open systems up to denial-of-service (DoS) and other kinds of attacks, experts have warned.

Finnish researchers at the University of Oulu announced Monday that they have found a vulnerability in the Internet Security Association and Key Management Protocol, or ISAKMP. The technology is used in IPsec virtual private network and firewall products from a range of networking companies, including giants Cisco and Juniper.

The severity of the problems varies by software vendor, according to an advisory issued jointly by the British National Infrastructure Security Coordination Centre (NISCC) and the Finnish CERT.

"These flaws may expose DoS conditions, format string vulnerabilities, and buffer overflows," the advisory said. All these could shut down devices and slow transmission of data across the Internet. In some cases, they could also allow hackers to execute code and hijack a device, NISCC warned.

The ISAKMP, which provides associations for other security protocols, is used to establish secure links over the public Internet. It is an important part of IPsec, which is used to encrypt packets and create secure tunnels for traffic travelling over the Internet and into a corporate network. Large companies with small branch offices use IPsec to securely connect their smaller offices to headquarters. Remote workers also use the technology to access their companies' internal networks.

Cisco and Juniper, two of the largest networking technology vendors, acknowledged that some of their products are at risk.

Cisco said the security flaw could cause devices to reset over and over, which could cause a temporary DoS attack. It did not mention the possibility of the device being taken over by an intruder.

The company is providing free software upgrades to fix the problem and has published a security advisory. The list of affected products includes Cisco IOS, Cisco PIX Firewall, Cisco Firewall Services Module, Cisco VPN 3000 Series Concentrators and the Cisco MDS Series SanOS, according to the alert.

The list of Juniper products affected include all of its M-series, T-series, J-series and E-series routers, as well as most versions of its Junos and JunoSe Security software. A Juniper representative said the company has been aware of the problem since June, so software issued on or after July 28 provide fixes for the flaw, the representative said.

The Openswan Project, which is IPsec software used on many Linux products, is also affected. The organisation behind the software released Openswan 2.4.2 in response to the advisory. The update can be downloaded from its Web site.

Networking gear vendor 3Com said it is looking into the matter to see if any of its products are affected. IBM and Microsoft said their products are not affected. A full list of companies that have responded to the alert can be found on the NISCC Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
85 out of 187 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment

Ion-toting Eee 1201N to hit UK in Janu...

Asus has confirmed its long-rumoured Eee PC 1201N, the first in the company's line of netbooks to use Nvidia's Ion graphics platform. The 1201N will also be one of the first netbooks... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters