ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Cisco reveals more router flaws

Marguerite Reardon CNET News.com

Published: 27 Jan 2005 12:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco on Wednesday announced it has uncovered three more security flaws in its routing software that could allow denial-of-service (DoS) attacks.

Just last week, Cisco posted a notice on its Web site warning users that routers connected to its IP telephony gear could be vulnerable to DoS attacks. The attacks involve floods of data packets forcing routers to constantly reload and reboot, which can keep legitimate users from accessing an overburdened Web site. Cisco has already posted a fix to last week's problem.

The vulnerabilities disclosed Wednesday are found in certain versions of Cisco's Internetwork Operating Software (IOS) software, and they also can cause DoS attacks. The company has made fixes and free software upgrades available on its site.

The most potentially serious flaw is one that deals with Cisco IP routers running the Border Gateway Protocol (BGP). This protocol, a language for routers in large networks to exchange information about each other, is widely used by carriers and Internet service providers.

According to Cisco's Web site, only routers configured with the command "bgp log-neighbor-changes" are vulnerable. Cisco said that this command is turned on by default on certain releases of IOS software.

A second flaw affects several versions of Cisco's lower-end routers that run the Multiprotocol Label Switching (MPLS) protocol. Vulnerable products include the Cisco 2600, 2800, 3600, 3700, 3800, 4500 and 4700 series routers and the 5300, 5350 and 5400 series Access Servers.

Cisco's high-end routers, such as the 7200, 7500 and 12000 series routers -- used by telephone operators and Internet service providers to shuttle traffic across the Net -- are not affected, Cisco said. The company's popular Catalyst Ethernet switches are also not impacted.

The final, and probably least serious, of the new flaws affects routers running Internet Protocol version 6. IPv6 has been designed to replace the current Internet Protocol version, IPv4. This vulnerability can only be exploited when a router is configured to process IPv6 packets, Cisco said. Because most routers on the Internet today still use IPv4, the security flaw will probably not cause any serious security problems.

One analyst said these security warnings are not much to worry about and should be considered a natural course of business. Companies across the technology landscape from Apple to Microsoft to Oracle are constantly updating customers about newly identified security vulnerabilities.

"Operating systems are always evolving," said Kevin Mitchell, an analyst with Infonetics Research. "Features are constantly being added. People pay attention to Cisco's reported flaws more closely because the company has such a huge installed base."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
53 out of 99 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Broadband Consultant - IP DSLAM / ADSL - Immediate Start!

Broadband Testing - Thomson CPE DSL Modems & Routers - Internet Protocol Suite & Wireless Networking Protocols - TR-069 - Linux / Ubuntu Apply Now! ...

Fix Protocol Analyst - Contract - London City / NY

Fix Protocol Analyst - Contract - London City / NY My client is seeking an experienced FIX protocol analyst to join their team on a contractual ...

Jnr Fix Protocol Contractor - London - Finance

Jnr Fix Protocol Contractor - London - Finance A financial institution in the centre of London is seeking a fix protocol engineer to join thier team. ...

On The Road Blog

Mobile Surfin’ USA

If everybody had a mobile – across the USA… OK, I’ll stop there. Actually, I’m not much of a Beach Boys fan. But betwixt a number of US-based events as I am, I think I’m more acutely... More

Post a comment

Gizmo Adds Business Enhancements and M...

Gizmo5 (formerly The Gizmo Project) has been my preferred program for IM text chat and audio calls (including PSTN calls worldwide) for quite some time now. The chat interface is clean... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment