Newsletter:

Skip Navigation LinksHome > News > Security > Cisco warns of IOS security flaws

Cisco warns of IOS security flaws

By Shaun Nichols
14 May 2007 04:40PM
Tags: cisco | warns | ios | security | flaws

Vulnerability could open door for network attacks.

Cisco Systems has warned administrators that several of the company's routers and switches could be vulnerable to attack.

The vulnerabilities lie within a little-used component in IOS, an operating system used to control Cisco's networking hardware.

IOS 11.3, 12.0, 12.1, 12.2, 12.3 and 12.4 all contain the vulnerability. The latest version of the software, IOS XR, is not affected.

An attacker could remotely exploit flaws in the FTP Server component of IOS to break into a network and steal data or execute malicious code. FTP is a protocol used to transfer files over a network.

IOS FTP Server is not enabled by default, and is usually used only to manage FTP servers. Cisco has issued an update that disables the component, but users can also manually disable FTP Server within IOS.

Cisco said that the offending component will be removed in all future IOS releases and will possibly be replaced by new FTP software at a later date.

The company recommends users to switch to IOS Secure Copy or Trivial File Transfer Protocol systems to transfer files.

Secunia rated the vulnerability 'moderately critical', the third of its five severity levels.

The security firm noted that, while the vulnerabilities allow attackers to view files and remotely execute code, the affected component is not enabled by default.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 




Product Reviews

Star Rating
Blink is an endpoint security product that functions as a network protector.
Star Rating
EndPointSecurity installs a small footprint agent on the machine.
Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Star Rating
Lumension offers a pair of products, Sanctuary Application Control and Sanctuary Device Control, that work in...
Star Rating
First, it is important to note that unlike previous versions of ZENworks, Novell ZENworks Endpoint Security...
Product Reviews now available on iTnews.com.au

TopTopics
(2960) -  telstra
(2862) -  microsoft
(2031) -  network
(1875) -  broadband
(1712) -  apple
(1582) -  security
(1513) -  mobile
(1101) -  internet
(1092) -  data
(1059) -  intel
(1034) -  blackberry
(976) -  ibm
(942) -  researchers
(827) -  windows
(807) -  vmware