• On GameFAQs: Is it OK to lay my Wii down on its side?
May 22, 2008 10:48 AM PDT

Cisco patches three critical flaws

by Robert Vamosi

On Wednesday, Cisco Systems issued three patches for critical vulnerabilities affecting Cisco Internetwork Operating System (IOS). The most serious of these affects the Cisco Voice Portal and the Secure Shell server (SSH) implementations.

Cisco says the first patch covers a vulnerability that exists in the Cisco Unified Customer Voice Portal (CVP) , which provides customer voice and video self-service integration. If the vulnerability is exploited, an authenticated user can create, modify, or delete a superuser account. In other words, successful exploitation may result in full control of the system.

The second patch covers the Secure Shell server (SSH) implementation in Cisco IOS, which contains multiple vulnerabilities. Exploitation may allow unauthenticated users to generate a spurious memory access error or, in certain cases, reload the device. Cisco notes that the IOS SSH server is an optional service that is disabled by default, but says its use is recommended as a security best practice for management of Cisco IOS devices.

According to Cisco, the third patch addresses three Secure Shell (SSH) vulnerabilities that exist in the Cisco Service Control Engine (SCE) that may result in system instability or a reload of the SCE. Cisco says the first vulnerability may be triggered during SSH log-in activity with brute force. The second vulnerability may be triggered with normal SSH log-in activity combined with simultaneous other SCE management actions. The third vulnerability may occur during SSH log-in using unique invalid authentication credentials.

Attacks against VoIP systems are becoming popular. At this year's Shmoocon, John Kindervag, senior security architect for Vigilar, said that public waiting areas in hospitals, conference rooms, and hotel rooms are particularly vulnerable to these kinds of attacks.

Bottom line: if you're running Cisco IOS, get the updates today.

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
advertisement
Click here!
Recent posts from Defense in Depth
Window Snyder to leave Mozilla
How to handle ID fraud's youngest victims
Is white listing going mainstream?
How Live OneCare changed the antivirus landscape
Express Scripts clients threatened with extortion
Study: DDoS attacks threaten ISP infrastructure
Security expert talks Russian gangs, botnets
Extortion used in Express Scripts database breach
Add a Comment (Log in or register)
by bernie.mcginn June 2, 2008 10:31 AM PDT
interesting post... thanks!
Reply to this comment
advertisement

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Defense in Depth

Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader

Defense in Depth topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right