Security checks crash Cisco routers

Red-faced networking giant Cisco has been forced to warn customers that its routers can crash when tested for security vulnerabilities by security scanning software programs.

John Leyden

Red-faced networking giant Cisco has been forced to warn customers that its routers can crash when tested for security vulnerabilities by security scanning software programs.

The defect, due to a fault in Cisco's IOS (Internet Operating System) software, can be exploited repeatedly to produce a consistent denial of service (DoS) attack, Cisco has admitted. The defect first came to light two months ago but is still an issue in the field, so Cisco has issued a reminder to customers.

Advertisement

Cisco customers using the affected IOS software releases - which include 11.3AA, and a number of 12.0 releases up to and including 12.0(6) - are urged to upgrade as soon as possible to later versions, which are not vulnerable to the defect.

Richard Stagg, senior security architect at Information Risk Management, said Cisco is blaming security tools when the problem is far wider.

"Cisco is obfuscating the fact that its routers have a weakness to denial of service attacks," said Stagg. "The idea that these denial of service attacks can be triggered by security scans is even more embarrassing."

The DoS aspect of the flaw was discovered by several different Cisco customers while they were conducting security scans of their networks. However, Cisco said it has still received no reports of malicious exploitation of the flaw.

Cisco's advisory states: "The described defect can be used to mount a consistent and repeatable denial of service attack on any vulnerable Cisco product, which may result in violations of the availability aspects of a customer's security policy. This defect by itself does not cause the disclosure of confidential information nor allow unauthorised access."

The flaw in IOS is exposed when unspecified security scanners test for the presence of two specific vulnerabilities that affect certain Unix-based systems. These vulnerabilities are unrelated to Cisco IOS software. However, a side effect of the tests means that a router can crash without warning.

During the test, the scanning program invokes the Telnet Environ option, #36, before the router is ready to accept it. This causes the router to reset itself unexpectedly.

In lieu of a software upgrade, Cisco has also detailed workarounds. These involve setting up an interactive log-in capability without using the Telnet service, thus mitigating the threat.

This vulnerability affects a wide range of Cisco's hardware line including series access servers, routers, access products and voice gateway products running vulnerable software.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Cisco fixes flaw in IOS software

Cisco Systems has made known a potentially devastating security vulnerability in its operating system software that could allow an attacker to intercept and modify traffic going to and from routers and switches.

Cisco works to fix switch glitch

Cisco has released a security advisory for its Arrowpoint switch, revealing that non-privileged users can either force a denial of service attack on the hardware or view files to which they do not have access rights.

Cisco patches firewall security hole

Cisco has been forced to alert users to a potentially devastating problem with its firewall product only days after launching a new security programme.

Cisco gigabit routers vulnerable to attack

Cisco has admitted that a defect in the software running on its Gigabit Switch Router family leaves them vulnerable to denial of service attacks.

Related whitepapers

Related jobs

Most watched

Social networking

Summit: How businesses should manage their brands online

In part one of V3.co.uk's interview with Dirk Singer, he dicusses social media monitoring strategies

RIM discusses new developer tools

Blackberry exec on the latest offerings for programmers

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Alcatel-Lucent logo

Summit: Networks swamped by information overload

Alcatel-Lucent's Neal Tilley talks about how enterprises and carriers can...

EU flag

Breach notification laws get green light

Privacy rights strengthened in Europe

Richard Thomas

Summit: Richard Thomas advises on handling the data deluge

Former Information Commissioner speaks out on government databases and data...

oracle sun

War of words escalates between EU and Oracle

Commission comes out fighting after criticism from Oracle and Washington

Primary Navigation