All the latest UK technology news, reviews and analysis

Cisco works to fix switch glitch

by James Middleton

01 Feb 2001

Be the first to comment

  • Tweet this

Cisco has released a security advisory for its Arrowpoint switch, revealing that non-privileged users can either force a denial of service (DoS) attack on the hardware or view files to which they do not have access rights.

The company has said that although there is a fix available for the DoS problem, it can only currently offer a workaround for the file viewing glitch.

Only the carrier class Arrowpoint, or Content Services, switch is affected on hardware platforms 11050, 11150, and 11800 running the WebNS software. The problem poses a threat once access to the command line interface is gained.

But even a non-privileged user with access to the command line can run a command which contains a filename that is the maximum length of the input buffer. This would cause the switch to reboot and perform a systems check, effectively putting the machine out of action for about five minutes.

Cisco said that commands which can be manipulated to do this include show script, clear script, show archive, clear archive, show log and clear log. Non-privileged users can also read files they would not normally have access to if they know the location of the data.

A fix is available for the DoS vulnerability by upgrading the switch's WebNS software to version 4.01(12s) or revision 3.10(71s). Cisco is offering the software upgrades free of charge.

The file system information disclosure vulnerability is scheduled to be fixed, but is currently unresolved. In the meantime, the company recommends a workaround by applying access control lists and additional firewalling to restrict access to the command line interface on the device. It is also advisable to disable Telnet access to the switch by adding the command: CS150(config)# telnet access disabled.

Workaround information is available here and here.

Details of the fixes and software upgrades are available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

2%

12%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

CISCO CCNP NETWORK ENGINEER

CISCO CCNP NETWORK ENGINEER - INVESTMENT BANKING - LONDON...

Business Analyst - Ecommerce - Retail - London

One of London's leading retailers is currently recruiting...

Project Manager / Business Analyst

Agile, Prince2. My client, a global ecommerce organisation...

E-Commerce Producer

E-Commerce Producer - Oxfordshire - Permanent My client...

To send to more than one email address, simply separate each address with a comma.