All the latest UK technology news, reviews and analysis

Cisco warns of DoS flaw in switches

by James Middleton

11 Jul 2003

Be the first to comment

  • Tweet this

Cisco is warning of a denial of service attack that affects certain models of switches in its Catalyst 4000, 5000 and 6000 lines.

After receiving eight connection attempts using a non-standard TCP flag combination, the switch will stop responding to further TCP connections to that particular service, effectively causing a denial of service.

The vulnerability affects only CatOS. Cisco said the CatOS for the Catalyst 4000 Series including models 2948G and 2980G/2980G-A, the Catalyst 5000 Series including models 2901, 2902 and 2926, and the Catalyst 6000 were affected.

The firm confirmed that, in order to re-establish functionality of that service, the switch must be rebooted as there is no available workaround. Cisco is offering free software upgrades to fix the problem.

The switch will continue to pass other switched traffic normally and the console is also not affected. Only the service to which connections were made will become unresponsive.

Cisco said that by exploiting this vulnerability, an attacker could prevent further use of the specified TCP-based service.

Depending on the configuration of the device, if SSH or Telnet are enabled and exploited the availability of those services could be affected, possibly resulting in a loss of management capability using those services.

UDP-based services such as Simple Network Management Protocol would still be available and unaffected.

Although the only solution is to reboot, it is possible to mitigate the exposure by configuring virtual local area network access control lists on the switch so that it will allow only legitimate hosts to connect to the desired services.

This must be combined with Unicast Reverse Path Forwarding, or some other anti-spoofing technique, on the network edge to protect against spoofed packets from outside the network.

Cisco said that the vulnerability was reported by a customer, but that it had received no reports of malicious use.

An advisory is available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Design Architect (Windows Database Application)

Software Design Architect (Windows Database Application...

Lead Java Developer - Mobile- Digital- Amsterdam

Lead Java Developer - Fast growing, young and international...

Graduate Software Support Engineer

Job Specification Graduate Support Engineer...

c# or asp.net Software Developer

Job Specification For: Software Developer...

To send to more than one email address, simply separate each address with a comma.