Advertisement
Promo

Security threats Toolkit

Flaws found in Cisco, Juniper and IBM kit

Dan Ilet ZDNet.co.uk

Published: 12 Apr 2005 17:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco, Juniper and IBM are suffering embarrassment today as a Home Office agency announced details of a software vulnerability that affects the vendors' products.

The National Infrastructure Co-Ordination Centre (NISCC) has published details of a denial-of-service vulnerability that can affect routers' ability to handle TCP traffic. Hackers commonly use denial-of-service attacks to flood target computers with data so they fail to work.

The NISCC Web site stated: "The impact of the ICMP TCP reset vulnerability varies by vendor and application, but in some deployment scenarios it is likely to be rated medium to high. If exploited, [this] could allow an attacker to create a denial-of-service condition against existing TCP connections, resulting in premature session termination."

Cisco is advising customers to update their products. It admitted that the problem affects PIX firewalls and all products running IOS — the operating system the majority of Cisco routers use.

"There is a free software fix available," said a Cisco spokesman. "It's an industry issue. We worked with NISCC to co-ordinate [the fix]." He added that the company had known about this for some time.

IBM admitted that its AIX operating system was also vulnerable, but the company appeared not have released detailed information yet. IBM was unable to respond in time for the publication of this article.

On NISCC's Web site, a Juniper spokesman wrote: "Juniper Networks M-series and T-series routers running certain releases of JUNOS software are susceptible to this vulnerability." Juniper also failed to respond to requests for comment.

Although the three vendors are unlikely to be the only companies affected by the vulnerability, their products form a large part of the Internet infrastructure.

NISCC has published details of how to characterise and fix the problem on its Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
66 out of 130 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters