All the latest UK technology news, reviews and analysis

Cisco warns of DoS flaw in IOS

by Robert Jaques

27 Jan 2005

Be the first to comment

  • Tweet this

Cisco has issued a security warning detailing a potentially serious flaw which could allow hackers to run denial of service attacks against customers using network equipment running the firm's IOS platform.

Vulnerable devices running IOS enabled for the Border Gateway Protocol (BGP) can be attacked with a malformed BGP packet, the networking giant warned.

Further reading

The vulnerability is present in any unfixed version of Cisco IOS, from the beginning of support for the BGP protocol, including versions 9.x, 10.x, 11.x and 12.x. However, only devices with the command 'bgp log-neighbor-changes' configured are at risk.

The BGP protocol is not enabled by default, and must be configured in order to accept traffic from an explicitly defined peer. Unless the malicious traffic appears to be sourced from a configured trusted peer, it would be difficult to inject a malformed packet, Cisco stated.

"A Cisco device receiving an invalid BGP packet will reset and may take several minutes to become fully functional. This vulnerability may be exploited repeatedly resulting in an extended DoS attack," a Cisco advisory warned.

"This bug may also be triggered by other means which are not considered remotely exploitable. The use of the commands show 'ip bgp neighbors' or 'debug ip bgp' [neighbour] updates can cause a router to reload if a router has previously queued a malformed packet.

"If there are no queued malformed packets, issuing these commands will have no harmful side effects."

Cisco advised users to check the version of IOS software running by logging into the device and using the 'show version' command to display the system banner.

IOS software will identify itself as 'Internetwork Operating System Software' or IOS. On the next line of output, the image name will be displayed between brackets, followed by 'Version' and the IOS release name.

Cisco has made free software available to address this problem which can be downloaded here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

PHP Web Developer OOP Symfony London – Award Winning Company!

Web Developer (PHP) OOP Symfony London – Award Winning...

Windows Engineer - Applications

Windows Server Applications Engineer 3rd Line Our market...

Technical Support - Edinburgh

My client have an exciting opportunity for a technical...

Senior ASP.NET Developer

Senior ASP.NET Developer Skills: ASP.NET, C#, VB, HTML...

To send to more than one email address, simply separate each address with a comma.