ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

VPNs at risk from security glitch

Marguerite Reardon CNET News.com

Published: 15 Nov 2005 10:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in a key Internet security protocol used by major networking products could open systems up to denial-of-service (DoS) and other kinds of attacks, experts have warned.

Finnish researchers at the University of Oulu announced Monday that they have found a vulnerability in the Internet Security Association and Key Management Protocol, or ISAKMP. The technology is used in IPsec virtual private network and firewall products from a range of networking companies, including giants Cisco and Juniper.

The severity of the problems varies by software vendor, according to an advisory issued jointly by the British National Infrastructure Security Coordination Centre (NISCC) and the Finnish CERT.

"These flaws may expose DoS conditions, format string vulnerabilities, and buffer overflows," the advisory said. All these could shut down devices and slow transmission of data across the Internet. In some cases, they could also allow hackers to execute code and hijack a device, NISCC warned.

The ISAKMP, which provides associations for other security protocols, is used to establish secure links over the public Internet. It is an important part of IPsec, which is used to encrypt packets and create secure tunnels for traffic travelling over the Internet and into a corporate network. Large companies with small branch offices use IPsec to securely connect their smaller offices to headquarters. Remote workers also use the technology to access their companies' internal networks.

Cisco and Juniper, two of the largest networking technology vendors, acknowledged that some of their products are at risk.

Cisco said the security flaw could cause devices to reset over and over, which could cause a temporary DoS attack. It did not mention the possibility of the device being taken over by an intruder.

The company is providing free software upgrades to fix the problem and has published a security advisory. The list of affected products includes Cisco IOS, Cisco PIX Firewall, Cisco Firewall Services Module, Cisco VPN 3000 Series Concentrators and the Cisco MDS Series SanOS, according to the alert.

The list of Juniper products affected include all of its M-series, T-series, J-series and E-series routers, as well as most versions of its Junos and JunoSe Security software. A Juniper representative said the company has been aware of the problem since June, so software issued on or after July 28 provide fixes for the flaw, the representative said.

The Openswan Project, which is IPsec software used on many Linux products, is also affected. The organisation behind the software released Openswan 2.4.2 in response to the advisory. The update can be downloaded from its Web site.

Networking gear vendor 3Com said it is looking into the matter to see if any of its products are affected. IBM and Microsoft said their products are not affected. A full list of companies that have responded to the alert can be found on the NISCC Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
85 out of 187 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Linux / Cisco Systems Engineers - Oxfordshire

The role requires a tenacious and imaginative approach to problem solving and provides an opportunity to work with an ever expanding, broad array of ...

Business Analyst, Gas and Power, Vendor, London

This vendor has a solid client base both in the US and throughout Europe. It has offices located worldwide and is currently looking to expand ...

Linux / Cisco Network Specialist UNIX, Linux, Cisco -Oxfordshire, South

Cisco Routers, Cisco IOS, Linux (RHEL4), Firewalls such as PIX & Firewall 1, TCP/IP, DNS, POP, SMTP, SNMP, proxies, email servers, PHP, MySQL, ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment