Advertisement
Promo

Security threats Toolkit

Cisco flaw creates an opening for insider attacks

Ingrid Marson ZDNet.co.uk

Published: 19 Aug 2004 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco released a security advisory on Wednesday warning that some Cisco networks could be vulnerable to denial-of-service attacks.

The problem occurs if a malformed packet is sent to a router that has been configured for the Open Shortest Path First (OSPF) protocol. This problem is limited to versions 12.0S, 12.2, and 12.3 of Cisco's IOS routing software.

Jon Oltsik, a network security analyst at the Enterprise Strategy Group, said the vulnerable versions and configuration are in common use and the effects of a successful attack could be devastating to an enterprise.

"If a hacker puts a certain request to the main router, then it could shut down the whole network," he said. But Oltsik believes that in practice the vulnerability requires both inside knowledge and Cisco expertise, which should limit the number of attacks. The most likely threat will come from former staff with a grievance.

"It's not like a Microsoft vulnerability that anyone with Internet access can exploit. You need specific knowledge to exploit this. An attack is most likely to come from a rogue employee who knows the configuration of the company's Cisco routers," said Oltsik.

Cisco has provided a patch for the security flaw and has also provided several workarounds for the problem. The full Cisco advisory has been posted here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
117 out of 217 people found this useful


Full Talkback thread

1 comment

  1. Although Cisco have stated that this flaw is only... John Bradley
Video icon

Video

Sentry Posts Blog

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters