Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Cisco reveals more router flaws

Marguerite Reardon CNET News

Published: 27 Jan 2005 12:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco on Wednesday announced it has uncovered three more security flaws in its routing software that could allow denial-of-service (DoS) attacks.

Just last week, Cisco posted a notice on its Web site warning users that routers connected to its IP telephony gear could be vulnerable to DoS attacks. The attacks involve floods of data packets forcing routers to constantly reload and reboot, which can keep legitimate users from accessing an overburdened Web site. Cisco has already posted a fix to last week's problem.

The vulnerabilities disclosed Wednesday are found in certain versions of Cisco's Internetwork Operating Software (IOS) software, and they also can cause DoS attacks. The company has made fixes and free software upgrades available on its site.

The most potentially serious flaw is one that deals with Cisco IP routers running the Border Gateway Protocol (BGP). This protocol, a language for routers in large networks to exchange information about each other, is widely used by carriers and Internet service providers.

According to Cisco's Web site, only routers configured with the command "bgp log-neighbor-changes" are vulnerable. Cisco said that this command is turned on by default on certain releases of IOS software.

A second flaw affects several versions of Cisco's lower-end routers that run the Multiprotocol Label Switching (MPLS) protocol. Vulnerable products include the Cisco 2600, 2800, 3600, 3700, 3800, 4500 and 4700 series routers and the 5300, 5350 and 5400 series Access Servers.

Cisco's high-end routers, such as the 7200, 7500 and 12000 series routers -- used by telephone operators and Internet service providers to shuttle traffic across the Net -- are not affected, Cisco said. The company's popular Catalyst Ethernet switches are also not impacted.

The final, and probably least serious, of the new flaws affects routers running Internet Protocol version 6. IPv6 has been designed to replace the current Internet Protocol version, IPv4. This vulnerability can only be exploited when a router is configured to process IPv6 packets, Cisco said. Because most routers on the Internet today still use IPv4, the security flaw will probably not cause any serious security problems.

One analyst said these security warnings are not much to worry about and should be considered a natural course of business. Companies across the technology landscape from Apple to Microsoft to Oracle are constantly updating customers about newly identified security vulnerabilities.

"Operating systems are always evolving," said Kevin Mitchell, an analyst with Infonetics Research. "Features are constantly being added. People pay attention to Cisco's reported flaws more closely because the company has such a huge installed base."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
56 out of 106 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment

Ion-toting Eee 1201N to hit UK in Janu...

Asus has confirmed its long-rumoured Eee PC 1201N, the first in the company's line of netbooks to use Nvidia's Ion graphics platform. The 1201N will also be one of the first netbooks... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters