You are here: silicon.com > Software > Security Strategy

Security Strategy

Cisco issues cyber attack alert

Has someone stolen 'the keys to the internet' again?

Tags: cisco

By Joris Evers

Published: 8 September 2005 09:10 BST

A serious flaw in Cisco Systems software puts computer networks at risk of cyber attack and has prompted security vendor Symantec to raise its internet threat level.

A vulnerability in Cisco's Internetwork Operating System (IOS) could be exploited to crash or remotely run malicious code on devices that run IOS, the San Jose, California, networking giant warned on Wednesday in a security advisory. IOS runs on Cisco's routers and switches, which make up a large portion of the internet's infrastructure.

Cisco said in its advisory: "Successful exploitation of the vulnerability on Cisco IOS may result in a reload of the device or execution of arbitrary code. Repeated exploitation could result in a sustained [denial of service] attack or execution of arbitrary code."

Cisco's warning prompted Symantec to raise its ThreatCon global threat index to Level 2, which means an attack is expected. Symantec said in an advisory: "Given the recent attention to exploitation of vulnerabilities in Cisco's IOS it is possible that this issue will see attempts at exploit development in the near term."

Cisco and Symantec both noted that there are no known exploits or attacks which take advantage of this latest IOS vulnerability. Cisco has software fixes available to correct the problem.

The vulnerability doesn't affect all versions of IOS, Cisco said. Furthermore, it only exists if the Firewall Authentication Proxy for FTP and Telnet Sessions is in use, Cisco said. That component of IOS handles authentication requests for file transfer and telnet sessions.

Affected devices are those running IOS versions 12.2ZH and 12.2ZL, 12.3, 12.3T, 12.4 and 12.4T, Cisco said. Users can log on to their Cisco device and enter the "show version" command to determine which version of IOS it is running, Cisco said. The company rates the issue as a "medium" urgency.

Symantec advises users who can't install the patch immediately to disable the Firewall Authentication Proxy for FTP and Telnet Sessions or limit access to the service to trusted hosts and networks.

This is not the first time Cisco has had a security scare this summer. During the Black Hat and Defcon security events in July, researcher Michael Lynn demonstrated he could gain control of a Cisco router by exploiting a known security flaw in IOS. The operating system had until then been perceived as impervious to such attacks.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Linux / Cisco Systems Engineers - Oxfordshire

IOS, Intel-based server hardware, TCP/IP, DNS and other Internet related technologies, such as proxies, web caches and email servers. ...

Systems Engineer, Windows 2003 / Cisco / Linux / VMWare- Oxfordshire

Unix, Red Hat, Mandrake, SUSE, Solaris, HP-UX, Cisco, Cisco IOS, Router, Firewall, PIX, Firewall 1, TCP/IP, DNS, DHCP, proxy, email, MS Exchange, ...

Systems Administrator / 2nd Line Support, Deeside, 20,000

Technical Requirements: - Exchange support & maintenance - Windows Server 2003 support & maintenance - Backup Exec - Proxy/Firewall/VPN - Antivirus & ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: