Cisco flaws send admins scrambling

Cisco has revealed a number of flaws in the operating system running on the majority of its switches and routers that could ultimately be exploited in denial-of-service (DoS) attacks.

The Cisco 6500 ships with IOS installed by default.
(Cisco 6500 image by Dmitry Barsky, CC2.0)

In many cases the flaws do not have temporary workarounds, forcing administrators to quickly update to patched software or remain vulnerable.

The company released advisories on several vulnerabilities in its IOS software overnight, following internal testing it had been conducting. IOS, not to be confused with Apple's iOS, is the operating system that runs on the majority of Cisco's routers and network switches. Cisco has released software updates to fix the issues, but there are only limited options for those who don't want to use the patch immediately. While Cisco often provides temporary workarounds that can be used while administrators make preparations to update their software, in this case there are no workarounds for the newly released vulnerabilities, or the workarounds significantly impact services to the point that they aren't practical.

The majority of the vulnerabilities are the result of how Cisco's IOS software processes specially crafted packets or messages including Session Initiation Protocol (SIP) messages used in voice over IP (VoIP) services and IPv6 packets. These holes could enable malicious users to cause devices that process SIP messages to reboot or become unstable. By continually exploiting this behaviour, they could deny services to legitimate users.

For those who don't want to install the patch, Cisco suggests the disabling of SIP processing completely — an option that isn't viable for those providing VoIP services.

For customers who must run SIP on vulnerable devices, Cisco recommends applying mitigation techniques such as allowing only legitimate devices to connect to the vulnerable ones and applying measures to guard against spoofing.

Other vulnerabilities have to do with how the operating system handles IPv6 packets. Malformed IPv6 packets could cause devices to reboot. Admins looking for a quick fix will have to drop IPv6 support completely. Many providers are moving to IPv6 from IPv4 due to the last IPv4 addresses being assigned in February.

The Cisco IOS software's Intrusion Prevention System (IPS) was also found to be vulnerable to attack. IPS is a packet inspection feature built into IOS that is designed to mitigate a range of network attacks. However, when processing specially crafted HTTP packets, devices could hang or crash and there is no temporary workaround.

The company has released advisories detailing what devices are vulnerable, but it has not publicly disclosed the vulnerabilities themselves. It has restricted this information to its registered customers, presumably to limit any opportunistic exploitation and give administrators time to plan the upgrades to their systems. Cisco said it had not seen any examples of the vulnerabilities being exploited in the wild.

IOS has been plagued by vulnerabilities in the past, including ones that have allowed users to skip paying their internet access charges.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

by http://t.co/vmlLt4bh: SA Health's journey to e-health: Implementing e-health services for an entire state is a... http://t.co/NVrBd9c5

Facebook investor to sue Nasdaq over alleged bungled orders: http://t.co/XGRsNzA4 ^LH

Combining @Ariba's network & @SAP's applications - "SAP eyes cloud super network with Ariba buy" http://t.co/jeMWEKpB

SA Health's journey to e-health: Implementing e-health services for an entire state is a daunting task, but, as ... http://t.co/Vwchau6N

RT @JamesVickery: Google warns users of DNSChanger malware http://t.co/DsHUnC5r

Upskill. RT @zdnetaustralia Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/PrFEBfqS ^ST

Google warns users of DNSChanger malware http://t.co/DsHUnC5r

National Botnet Network coming: Earthwave http://t.co/t49r3IV0

Surely IT is more than just a game? http://t.co/WvSk0C0N

RT @JLLLOW: Revolution. RT @zdnetaustralia: Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/rdjqdACC

Revolution. RT @zdnetaustralia: Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/rdjqdACC

Google has joined in on the chorus of organisations warning users about DNSChanger infections http://t.co/ysaIHiuG ^ML

Akku Asus A32-K72 Original,Kompatibler Ersatz akku für Li-ion Asus A32-K72 Original Laptop Akkus Asus A32-K72 Original,A32-K72 Original...

4 hours ago by akkuakku on HP Compaq 6730b

It is great to see the NSW government taking this step, however there's plenty of home-grown talent loeaving or being rediverted due to l...

4 hours ago by Aceyducey on NSW Govt appoints Silicon Valley champion

Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/EpY9YiFg ^ST

by http://t.co/vmlLt4bh: JobWatch: where the jobs are: The latest analysis on online job ads from the Department ... http://t.co/nh1wg7Y6

@chieftech @zdnetaustralia that's a fair call. Still an area that requires consideration work. BYOD = BYOViruses & Malware :)

JobWatch: where the jobs are http://t.co/Lqo8BNVT

EMC hones focus on hybrid cloud big data Hardware News ZDNet Australia: EMC has launched 42 prod... http://t.co/uR56HXDz #bigdata #blogs

Are specific gaming development degrees bollocks? http://t.co/z2zbaWvT ^ST

#NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/GPrIXH4F via @johnW3LLS #govcamp

JobWatch: where the jobs are: The latest analysis on online job ads from the Department of Education, Employment... http://t.co/qJce42h2

RT @johnW3LLS: #NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/JDSdSxWu #gov2au

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

What Microsoft won't tell you about Windows 7 licensing http://t.co/Y2e6sXdI #Win7

#Android fragmentation steers Vic Health - @ZDNet Australia : http://t.co/chrmWl7B

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic Healt... http://t.co/VTbMBy5A #android #news

by http://t.co/vmlLt4bh: Android fragmentation steers Vic Health: Fragmentation issues in Android were a key conc... http://t.co/wOmHdAav

Android fragmentation steers Vic Health http://t.co/CqTImM5l

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic... http://t.co/3ssDp1SW http://t.co/KpTZdvuO

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/NnjPEqSu

Android fragmentation steers Vic Health http://t.co/jcB7UGer

Chrome beats Internet Explorer in global Web browser race | ZDNet http://t.co/7G7xMfJj

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/HLdurfS5

Mining the social data stream for deeper customer insight | via @ZDNet http://t.co/x4xouPQh)

Android fragmentation steers Vic Health http://t.co/A6SJkfJw

But this is the thing. There are still plenty of good-quality graduates whose skills can raise seasoned professional eyebrows... if they ...

6 hours ago by techkid on Skills shortage: companies being too picky?

I wouldn't have called Vista cheesy. Its GUI was pretty slick (and indeed handed on to Windows 7). It was, however, poorly implemented, h...

6 hours ago by techkid on Microsoft admits Vista was 'cheesy'

Thanks Nelson, it should be right now.

-Michael.

6 hours ago by Mukimu on Ausgrid network to talk back to operators

I guess the mouse was a necessary evil at the time. I mean, yes, keyboard shortcuts in the right hands are faster than any mouse action (...

6 hours ago by techkid on Microsoft admits Vista was 'cheesy'

fyi google may always lie

6 hours ago by rt luvs youh on Google shows we're killing our language

they probaly always lie about in4mation bout people

6 hours ago by rt luvs youh on Google shows we're killing our language

$6.7million, now we know the price to the tax payer of a government IT project clean up. You've got to ask the question don't you: why o...

7 hours ago by Takenforgranted on Vic scraps HealthSMART system

why some mp4 files with higher frame width can not be played in my 3m mp180??

8 hours ago by cyrusmann_ymail.com on 3M MP180 Pocket Projector

Unfortunately there is NO such place as Nelson's Bay. It's Nelson Bay!! Probably not your fault for the error, as your Media Release prob...

8 hours ago by Nelson on Ausgrid network to talk back to operators

@Wow - thats one of the benefits of the iPad (and tablets in general). They are one of the most generation neutral products ever made. ...

10 hours ago by Gav on Westpac board goes paperless with iPads

and why is this such a super idea? http://www.itnews.com.au/News/301778,thousands-affected-in-billing-cloud-breach.aspx oh, yeah, right...

10 hours ago by btone on Fed Govt steps up on shared cloud plan

Wow, seems like a fantastic initiative that helps to save the environment. It must have taken a lot of convincing to get the Board to mov...

11 hours ago by Wow on Westpac board goes paperless with iPads

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

11 hours ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

11 hours ago by jeff_syd on Westpac board goes paperless with iPads

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

22 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

22 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

23 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

23 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

23 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

1 day ago by debsteele on Vic scraps HealthSMART system

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar