Cisco admits to serious PIX firewall flaw

Cisco last week admitted that two security vulnerabilities affecting its PIX firewalls could leave corporate networks open to attack.

John Leyden, Network News

Cisco last week admitted that two security vulnerabilities affecting its PIX firewalls could leave corporate networks open to attack.

In an interim security notice, the vendor acknowledged the existence of two related vulnerabilities that both cause its Secure PIX Firewalls to interpret FTP (File Transfer Protocol) commands out of context, leaving the networks behind the firewalls open to penetration.

Advertisement

Cisco said that in certain configurations "it is possible to fool the PIX stateful inspection into opening up arbitrary TCP ports, which could allow attackers to circumvent defined security policies".

All Cisco Secure PIX Firewalls with software versions up to and including 4.2(5), 4.4(4), and 5.0(3), that are configured to provide access to FTP services, are at risk from both vulnerabilities. Cisco admitted that the problem means any Cisco Secure PIX Firewall that has enabled the fix-up protocol FTP command could allow unauthorised data to reach the network it is designed to protect.

Deri Jones, managing director of security tester NTA Monitor, described the issue as "serious", particularly because Cisco's offering is currently the third most popular firewall in the market.

"To Cisco's credit it has issued a bulletin, but has not yet found any solutions. This will not be trivial to address and may take it some time," warned Jones.

Clive McCafferty, managing director of security consultant CenturyCom, said that many users, which include BT, use Cisco's PIX firewalls for managed services.

"This could allow an attacker to send spurious stuff and then launch an attack when a port is open," said McCafferty.

The first vulnerability, which remains unfixed, is exercised when a client inside the firewall browses to an external server and selects a link that the firewall interprets as two or more FTP commands. The client begins an FTP connection as expected, and at the same time unexpectedly executes another command opening a separate connection through the firewall.

The only solution Cisco currently suggests for this problem is disabling incoming FTP services. Any server that permits internal clients to make arbitrary outbound FTP connections may be vulnerable to this issue.

The second, related problem is exercised when the firewall receives an error message from an internal FTP server containing an encapsulated command that the firewall interprets as a distinct command. This can be exploited to open a separate connection through the firewall.

Both vulnerabilities are due to the command fix-up protocol FTP (portnum), which is enabled by default on the Cisco Secure PIX Firewall. To exploit the security flaws, attackers must be able to make connections to an FTP server protected by the PIX Firewall.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

More problems for Cisco firewalls

Motherboard fault 'impossible to fix'

Firewall flaw threatens server shutdown

Check Point Software has admitted that an as yet unfixed flaw in its market leading firewall product, Firewall-1, leaves it vulnerable to denial of service attacks.

Cisco routers on crash course

Cisco has urged users to disable web based management of its routers after a serious, and as yet unfixed, vulnerability that could allow hackers to crash networks came to light.

Cisco bug leaves networks wide open

Cisco has admitted that a vulnerability with versions of its Lan switching software permits unauthorised configuration changes on a Catalyst switch.

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Google Chrome

Microsoft has no need to worry about Chrome OS

Redmond may actually welcome the new arrival

Dr Aladdin Ayesh

Is it time for the Turing Test to retire?

It is nearly 60 years since Alan Turing devised a...

Security double standards

Broadband provider Tiscali has launched new figures showing an alarming...

Beach

Top 10 holiday gadgets

A wry look at the must-have beach items for any...

Primary Navigation