October 19, 2005 2:54 PM PDT

Bug exposes Cisco switches to attacks

Cisco Systems' CSS 11500 Series Content Services Switches configured with Secure Socket Layer, or SSL, termination services are vulnerable to a denial of service, or DoS, attack, Cisco said in an advisory Wednesday. The switch is designed for use in data centers and performs an analysis of protocol headers and directs data traffic based on policies. Integrated SSL modules can simplify the management of digital certificates.

However, a memory corruption that occurs when the switch processes a malformed digital client certificate could cause the switch to reload, Cisco said. The flaw only exists if a switch is configured to support SSL termination services, which it is not by default, the networking giant said. Cisco has a fix for the vulnerability, which is rated "moderate" by the French Security Incident Response Team, a research outfit.

 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

Inside CNET News

1-2 of 12

Scroll Left Scroll Right

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (0.00%) 0.00 19.90
Dow Jones Industrials (0.00%) 0.00 12,801.23
S&P 500 (0.00%) 0.00 1,342.64
NASDAQ (0.00%) 0.00 2,903.88
CNET TECH (0.00%) 0.00 2,032.01
  Symbol Lookup