Advertisement
Promo

Security threats Toolkit

Cisco warns of more router vulnerabilities

Richard Thurston ZDNet.co.uk

Published: 14 Feb 2007 12:24 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The intrusion-prevention capabilities of Cisco's routers are prone to attack, after the networking giant revealed two vulnerabilities in its key operating system.

The vulnerabilities affect those versions of Cisco's Internetwork Operating System (IOS) that start with "12.3" and "12.4". Almost all Cisco routers run a version of IOS. The flaws allow a hacker to circumvent the IPS protection built into the affected routers and also cause routers to crash.

IPS is an inspection feature found in many networking products, including those from Cisco, which aims to block unauthorised network access and malicious code in real time.

In a security advisory, Cisco said there were two vulnerabilities: a fragmented packet evasion weakness, which could lead to the IPS being circumvented, and an ATOMIC.TCP regular expression denial-of-service vulnerability. Exploitation of the first weakness "may result in an attacker being able to evade detection by an IOS IPS device. This could allow protected systems to be covertly attacked," Cisco warned. A hacker exploiting the second vulnerability "may cause an IOS IPS device to crash".

Cisco urged IT managers who run affected routers to patch the IOS.

Last month, Cisco found two other vulnerabilities in IOS. The first weakness could lead to a denial-of-service attack, while the second one allows hackers to execute malicious code on the device in question. Following news of the vulnerabilities, Cisco made patches available.

Cisco's routers are the most popular enterprise routers in the world. As such, IOS is the network operating system that the majority of hackers tries to exploit.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters