SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Flaws found in Cisco switches, routers

Flaws found in Cisco switches, routers

By:  Linda Leung  On: 19 Dec 2007 For: Network World (U.S.) Creator

The network equipment maker says the problem could result in denial-of-service attacks

FRAMINGHAM - Cisco Systems has alerted customers that a flaw in its Firewall Services Module could result in a reload of the module, or if exploited repeatedly, could result in a sustained denial-of-service attack.

FWSM is an integrated firewall module for Cisco Catalyst 6500 switches and Cisco 7600 Series routers.

In its security alert issued Wednesday, Cisco says there are "no known instances of intentional exploitation of this issue," but that it has "observed data streams that appear to be unintentionally triggering this vulnerability."

According to the security advisory, the security hole could be "triggered with standard network traffic, which is passed through the Application Layer Protocol Inspection process."

The only FWSM release affected by this vulnerability is FWSM System Software version 3.2(3). FWSM software version 3.2(4) contains the fixes for the vulnerability and will be available for download the week beginning Dec. 31 at this URL.

A workaround for this vulnerability can be found now at the security advisory.


Sign up for our Newsletters












Print |  Views: 586   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Linda Leung Linda Leung is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Legal flap over Defcon talk exposes divide on security flaws
Legal flap over Defcon talk exposes divide on security flawsCritics of the temporary restraining order issued last Saturday by a federal judge in Boston have labeled it an infringement of the students' U.S. First Amendment rights and an example of prior restraint on free speech
iPhone 2.0 security still not up to snuff
iPhone 2.0 security still not up to snuffThird-party tools and secure applications will bring the necessary security, but they're still months away, analysts say
Microsoft, researchers spar over Windows bug
Microsoft, researchers spar over Windows bugIt was the software maker's first critical vulnerability of 2008, but the company downplayed its significance. Now, subcribers to a security mailing list are told the dangers are greater than originally thought
Yes, you can ... making a VPN gateway support the iPhone
everybody wants an iphone ... but what about the security issues? jamey heary, a security consulting engineer at cisco, gets into the geeky details of how to cisco's ios and asa lines play well with apple's smart phone on the cisco subnet.got some hands-on advice for th
blog comments powered by Disqus