You are here: silicon.com > Software > Security Strategy

Security Strategy

Cisco plugs DoS hole

Warning over denial of service risk...

Tags: dos, patch, cisco

By Dawn Kawamoto

Published: 25 May 2007 08:51 GMT

Cisco Systems has released a security patch to fix vulnerabilities in a number of its products that are at risk of a denial of service (DoS) attack.

The vulnerabilities are found in a third-party cryptographic library in Cisco IOS, Cisco IOS XR, Cisco PIX and ASA Security Appliances, Cisco Firewall Module and Cisco Unified CallManager products, according to a security advisory issued by Cisco.

The security flaws could allow attackers to send a few small packets through the routers to shut down the network in a DoS attack, said Johannes Ullrich, chief research officer for the Sans Institute, which issued a security notice.

Ullrich said: "In most DoS attacks, you just send more traffic than the network can handle. But in this case, the attacker only has to send a few packets. That takes up less of their bandwidth and makes it very easy to resend these packets again and again."

The vulnerabilities can be exploited without a valid username or password, given some of the older Cisco products have the cryptographic library set to default. And while attackers may be able to launch a DoS attack, they are not known to gain access to information that has already been encrypted, Cisco noted.

In its advisory, Cisco includes various links for downloading fixes, as well as offering suggestions for potential workarounds.

Although the vulnerabilities affect a wide range of Cisco products, no exploits have yet surfaced, Ullrich said.

Cisco has issued several security advisories this year involving its routers. In January, the networking giant warned it had found three security flaws in its software which operates its routers and switches. And in February, Cisco alerted users that its intrusion prevention technology in its routers could be susceptible to an attack, due to vulnerabilities in its key operating system.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Unix Systems Engineer / Systems Administration

Shell, Bash, Perl, PHP, Python etc) Cisco IOS, Cisco Routers, Cisco Switches, Network Monitoring tools (such as, Nagios, Cacti) Linux Systems ...

Network Engineer

Cisco IOS, ipsec, VPN, pptp, wireless wpa, smtp, pop 3, imap, SQL, group policy, exchange 2007, active directory, 2003, 2008, firewall experience, ...

IT Systems Consultant

MS Server2003; SQL Server; ISA Server; Active Directory * Sun Solaris / Cisco IOS (Desirable) * Project Management / Requirements Capture If you are ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: