ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec 'expecting Net attack'

Joris Evers CNET News.com

Published: 08 Sep 2005 09:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious flaw in Cisco software puts computer networks at risk of cyberattack and has prompted security vendor Symantec to raise its Internet threat level.

A vulnerability in Cisco's Internetwork Operating System (IOS) could be exploited to crash or remotely run malicious code on devices that run IOS, the networking giant warned on Wednesday in a security advisory. IOS runs on Cisco's routers and switches, which make up a large portion of the Internet's infrastructure.

"Successful exploitation of the vulnerability on Cisco IOS may result in a reload of the device or execution of arbitrary code," Cisco said in its advisory. "Repeated exploitation could result in a sustained DoS attack or execution of arbitrary code."

Cisco's warning prompted Symantec to raise its ThreatCon global threat index to Level 2, which means an attack is expected. "Given the recent attention to exploitation of vulnerabilities in Cisco's IOS it is possible that this issue will see attempts at exploit development in the near term," Symantec said in an advisory.

Symantec and Cisco both noted that there are no known exploits or attacks that take advantage of this latest IOS vulnerability. Cisco has software fixes available to correct the problem.

The vulnerability disclosed on Wednesday doesn't affect all versions of IOS, Cisco said. Furthermore, the vulnerability exists only if the Firewall Authentication Proxy for FTP and Telnet Sessions is in use, Cisco said. That component of IOS handles authentication requests for file transfer and telnet sessions.

Affected are those devices running IOS versions 12.2ZH and 12.2ZL, 12.3, 12.3T, 12.4 and 12.4T, Cisco said. Users can log on to their Cisco device and enter the "show version" command to determine which version of IOS it is running, Cisco said. The company rates the issue as a "medium" urgency.

Symantec advises users who can't install the patch immediately to disable the Firewall Authentication Proxy for FTP and Telnet Sessions or limit access to the service to trusted hosts and networks.

Cisco has had a hot summer when it comes to security. During the Black Hat and Defcon security events in July, researcher Michael Lynn demonstrated he could gain control of a Cisco router by exploiting a known security flaw in IOS. The operating system had until then been widely perceived as impervious to such attacks.

Cisco and ISS — Lynn's employer — had agreed to pull the presentation, but researcher Lynn quit his job and gave the talk anyway. Cisco and ISS sued Lynn after his presentation and hackers rallied behind the researcher.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
33 out of 80 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Systems Engineer, Windows 2003 / Cisco / Linux / VMWare- Oxfordshire

Unix, Red Hat, Mandrake, SUSE, Solaris, HP-UX, Cisco, Cisco IOS, Router, Firewall, PIX, Firewall 1, TCP/IP, DNS, DHCP, proxy, email, MS Exchange, ...

Systems Administrator / 2nd Line Support, Deeside, 20,000

Technical Requirements: - Exchange support & maintenance - Windows Server 2003 support & maintenance - Backup Exec - Proxy/Firewall/VPN - Antivirus & ...

B2B connectivity Network analyst city based investment bank 6 months

Skills Exp of B2B network architect design in finance environments Detailed exp of Cisco Catalyst products Detailed understanding and exp of BGP, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment