Alcatel security slip-up threatens customers

The US based Computer Emergency Response Team (CERT) has released an advisory strongly urging Alcatel customers using certain types of switches to upgrade the software running them, after a massive security slip-up was discovered.

It has been revealed that any network device running Alcatel Operating System (AOS) version 5.1.1 actually has a whopping back door in it. A telnet server was found running on certain switches and network devices. When this telnet server is accessed there is no request from the network device for authentication of any kind.

"An attacker can gain full access to any device running AOS version 5.1.1, which can result in, but is not limited to, unauthorized access, unauthorised monitoring, information leakage, or denial of service." CERT said in their advisory.

The telnet server was put there for testing purposes when the operating system was still being developed and it is unclear why it was not removed.

"Due to an oversight, this access was not removed prior to product release," CERT said.

A particularly damaging aspect of this vulnerability is the ease by which it is exploited. The test code was designed to allow engineers to easily access the device. No special software tools or superior knowledge of computer security or networks is required to successfully hack into a device running AOS.

Concerned administrators can upgrade to a newer version of AOS.

CERT has rated this back door as serious.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue All I want for Xmas is Telstra pricing
    Five consecutive days without broadband has led me to what seemed at the time to be an act of desperation: contemplating signing up for Telstra's 100Mbps cable modem service.
  • Array Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • More blogs »

Tags

Back to top

Featured