Cisco admits to serious PIX firewall flaw

Cisco last week admitted that two security vulnerabilities affecting its PIX firewalls could leave corporate networks open to attack.

John Leyden, Network News

Cisco last week admitted that two security vulnerabilities affecting its PIX firewalls could leave corporate networks open to attack.

In an interim security notice, the vendor acknowledged the existence of two related vulnerabilities that both cause its Secure PIX Firewalls to interpret FTP (File Transfer Protocol) commands out of context, leaving the networks behind the firewalls open to penetration.

Advertisement

Cisco said that in certain configurations "it is possible to fool the PIX stateful inspection into opening up arbitrary TCP ports, which could allow attackers to circumvent defined security policies".

All Cisco Secure PIX Firewalls with software versions up to and including 4.2(5), 4.4(4), and 5.0(3), that are configured to provide access to FTP services, are at risk from both vulnerabilities. Cisco admitted that the problem means any Cisco Secure PIX Firewall that has enabled the fix-up protocol FTP command could allow unauthorised data to reach the network it is designed to protect.

Deri Jones, managing director of security tester NTA Monitor, described the issue as "serious", particularly because Cisco's offering is currently the third most popular firewall in the market.

"To Cisco's credit it has issued a bulletin, but has not yet found any solutions. This will not be trivial to address and may take it some time," warned Jones.

Clive McCafferty, managing director of security consultant CenturyCom, said that many users, which include BT, use Cisco's PIX firewalls for managed services.

"This could allow an attacker to send spurious stuff and then launch an attack when a port is open," said McCafferty.

The first vulnerability, which remains unfixed, is exercised when a client inside the firewall browses to an external server and selects a link that the firewall interprets as two or more FTP commands. The client begins an FTP connection as expected, and at the same time unexpectedly executes another command opening a separate connection through the firewall.

The only solution Cisco currently suggests for this problem is disabling incoming FTP services. Any server that permits internal clients to make arbitrary outbound FTP connections may be vulnerable to this issue.

The second, related problem is exercised when the firewall receives an error message from an internal FTP server containing an encapsulated command that the firewall interprets as a distinct command. This can be exploited to open a separate connection through the firewall.

Both vulnerabilities are due to the command fix-up protocol FTP (portnum), which is enabled by default on the Cisco Secure PIX Firewall. To exploit the security flaws, attackers must be able to make connections to an FTP server protected by the PIX Firewall.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

More problems for Cisco firewalls

Motherboard fault 'impossible to fix'

Firewall flaw threatens server shutdown

Check Point Software has admitted that an as yet unfixed flaw in its market leading firewall product, Firewall-1, leaves it vulnerable to denial of service attacks.

Cisco routers on crash course

Cisco has urged users to disable web based management of its routers after a serious, and as yet unfixed, vulnerability that could allow hackers to crash networks came to light.

Cisco bug leaves networks wide open

Cisco has admitted that a vulnerability with versions of its Lan switching software permits unauthorised configuration changes on a Catalyst switch.

Related whitepapers

Related jobs

Most watched

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he dicusses social media monitoring strategies

RIM discusses new developer tools

Blackberry exec on the latest offerings for programmers

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Rich Media

Summit: Is the ECM industry up to the information overload challenge? Part 2

In part two of our summit special, Autonomy, Alfresco and...

Video: Mike Altendorf, EMC Consulting interview

As part of the V3 Summit, Altendorf discusses customer experiences...

Summit: IBM's Nick Davis on collaboration

IBM's collaboration technologist outlines tools that can aid working together

adobe

Adobe cuts more jobs

Nearly 700 to go worldwide

Primary Navigation