This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Cisco Gear Hackable, Net Security Risk Rises

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.techweb.com/wire/security/170701227
September 07, 2005
"Cisco on Wednesday confirmed that routers and other devices running the newest versions of its IOS (Internetwork Operating System) are vulnerable to serious attack. The San Jose, Calif.-based network hardware maker published a security advisory* and recommended that users either upgrade to alternate editions or install fixed versions of IOS. For its part, security giant Symantec immediately raised its overall Internet threat to "Level 2" from "1" earlier in the day. The last time Symantec had its threat set to "2" was during the Zotob attacks of August. "Given the recent attention to exploitation of vulnerabilities in Cisco's IOS it is possible that this issue will see attempts at exploit development in the near term," wrote Symantec researchers in an alert to customers of its DeepSight Threat Management System. The flaw is in the Firewall Authentication Proxy for FTP and/or Telnet Sessions in later versions of IOS – 12.2 through 12.4 – and might result in either a denial-of-service (DoS) attack which would likely bring down the device or possibly a more dangerous scenario, where the attacker gains complete control of the device. Or both…"

* http://www.cisco.com/warp/public/707/cisco…y.shtml#details
Cisco IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow
Document ID: 66269
Revision 1.0
For Public Release 2005 September 7
"…Cisco IOS Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack when processing the user authentication credentials from an Authentication Proxy Telnet/FTP session. To exploit this vulnerability an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt…
Software Versions and Fixes
When considering software upgrades, please also consult http://www.cisco.com/en/US/products/produc…es_listing.html and any subsequent advisories to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center ("TAC") for assistance…"

:ph34r:
FYI…

- http://secunia.com/advisories/16719/
Release Date: 2005-09-08
Critical: Moderately critical
Impact: DoS
System access
Where: From local network
Solution Status: Vendor Patch
OS: Cisco IOS 12.x, Cisco IOS R12.x
The vulnerability is reported in the following versions:
* 12.2ZH and 12.2ZL based trains
* 12.3 based trains
* 12.3T based trains
* 12.4 based trains
* 12.4T based trains
Solution:
Fixes are available (see patch matrix in vendor advisory)
- http://www.cisco.com/warp/public/707/cisco….shtml#software
Provided and/or discovered by: Reported by vendor.
Original Advisory:
http://www.cisco.com/warp/public/707/cisco…uth_proxy.shtml
Other References:
US-CERT VU#236045:
http://www.kb.cert.org/vuls/id/236045 …"

:ph34r:
FYI…

Cisco IOS Firewall vulnerability update
- http://isc.sans.org/diary.php?storyid=699
Last Updated: 2005-09-23 20:44:10 UTC
"Cisco released an update to the sept 7th vulnerability release with regards to Cisco IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow. This one could be a MAJOR issue for people running Cisco IOS firewall with authentication proxies for ftp and telnet…
http://www.cisco.com/en/US/products/produc….shtml#software
Revision 1.1
2005-September-22
Added 12.2SG, 12.2SEC, and 12.2SXF releases to Software Version and Fixes …"

:ph34r: