ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Cisco releases patches for router vulnerabilities

Dawn Kawamoto CNET News.com

Published: 25 May 2007 09:43 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco has released a security patch to fix vulnerabilities in a number of its products that are at risk of a denial-of-service attack.

The vulnerabilities are found in a third-party cryptographic library in Cisco IOS, Cisco IOS XR, Cisco PIX and ASA Security Appliances, Cisco Firewall Module and Cisco Unified CallManager products, according to a security advisory issued by Cisco.

The security flaws could allow attackers to send a few small packets through the routers to shut down the network in a denial-of-service (DoS) attack, said Johannes Ullrich, chief research officer for the Sans Institute, which issued a security notice on Wednesday.

"In most DoS attacks, you just send more traffic than the network can handle. But in this case, the attacker only has to send a few packets," Ullrich said. "That takes up less of their bandwidth and makes it very easy to resend these packets again and again."

The vulnerabilities can be exploited without a valid username or password, given some of the older Cisco products have the cryptographic library set to default. And, while attackers may be able to launch a DoS attack, they are not known to gain access to information that has already been encrypted, Cisco noted.

In its advisory, Cisco includes various links for downloading fixes, as well as offering suggestions for potential workarounds.

Although the vulnerabilities affect a wide range of Cisco products, no exploits have yet surfaced, Ullrich noted.

Cisco has issued several security advisories this year involving its routers. In January, the networking giant warned that it had found three security flaws in its software that operates its routers and switches. And, in February, Cisco alerted users that its intrusion prevention technology in its routers could be susceptible to an attack, due to vulnerabilities in its key operating system.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Linux / Cisco Systems Engineers - Oxfordshire

IOS, Intel-based server hardware, TCP/IP, DNS and other Internet related technologies, such as proxies, web caches and email servers. The role ...

NOC engineer needed! Gain formal Juniper Qualifications - Hampshire

Based from company HQ in Hampshire, your role will be to come onboard as a 2nd / 3rd line network support engineer providing 24 x support on the ...

UNIX / Linux Infrastructure Operations Engineer - UNIX / Linux - Oxfordshire, South

Experience with Cisco routers and switches, Cisco IOS, Intel-based server hardware, TCP/IP, DNS and other Internet related technologies, such as ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment