AplusWebMaster
Topic Starter
FYI…
- http://www.techweb.com/wire/security/170701227
September 07, 2005
"Cisco on Wednesday confirmed that routers and other devices running the newest versions of its IOS (Internetwork Operating System) are vulnerable to serious attack. The San Jose, Calif.-based network hardware maker published a security advisory* and recommended that users either upgrade to alternate editions or install fixed versions of IOS. For its part, security giant Symantec immediately raised its overall Internet threat to "Level 2" from "1" earlier in the day. The last time Symantec had its threat set to "2" was during the Zotob attacks of August. "Given the recent attention to exploitation of vulnerabilities in Cisco's IOS it is possible that this issue will see attempts at exploit development in the near term," wrote Symantec researchers in an alert to customers of its DeepSight Threat Management System. The flaw is in the Firewall Authentication Proxy for FTP and/or Telnet Sessions in later versions of IOS – 12.2 through 12.4 – and might result in either a denial-of-service (DoS) attack which would likely bring down the device or possibly a more dangerous scenario, where the attacker gains complete control of the device. Or both…"
* http://www.cisco.com/warp/public/707/cisco…y.shtml#details
Cisco IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow
Document ID: 66269
Revision 1.0
For Public Release 2005 September 7
"…Cisco IOS Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack when processing the user authentication credentials from an Authentication Proxy Telnet/FTP session. To exploit this vulnerability an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt…
Software Versions and Fixes
When considering software upgrades, please also consult http://www.cisco.com/en/US/products/produc…es_listing.html and any subsequent advisories to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center ("TAC") for assistance…"

- http://www.techweb.com/wire/security/170701227
September 07, 2005
"Cisco on Wednesday confirmed that routers and other devices running the newest versions of its IOS (Internetwork Operating System) are vulnerable to serious attack. The San Jose, Calif.-based network hardware maker published a security advisory* and recommended that users either upgrade to alternate editions or install fixed versions of IOS. For its part, security giant Symantec immediately raised its overall Internet threat to "Level 2" from "1" earlier in the day. The last time Symantec had its threat set to "2" was during the Zotob attacks of August. "Given the recent attention to exploitation of vulnerabilities in Cisco's IOS it is possible that this issue will see attempts at exploit development in the near term," wrote Symantec researchers in an alert to customers of its DeepSight Threat Management System. The flaw is in the Firewall Authentication Proxy for FTP and/or Telnet Sessions in later versions of IOS – 12.2 through 12.4 – and might result in either a denial-of-service (DoS) attack which would likely bring down the device or possibly a more dangerous scenario, where the attacker gains complete control of the device. Or both…"
* http://www.cisco.com/warp/public/707/cisco…y.shtml#details
Cisco IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow
Document ID: 66269
Revision 1.0
For Public Release 2005 September 7
"…Cisco IOS Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack when processing the user authentication credentials from an Authentication Proxy Telnet/FTP session. To exploit this vulnerability an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt…
Software Versions and Fixes
When considering software upgrades, please also consult http://www.cisco.com/en/US/products/produc…es_listing.html and any subsequent advisories to determine exposure and a complete upgrade solution.
In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center ("TAC") for assistance…"