Version: 2008
  • On mySimon: Peg Perego John Deere Utility Tractor

December 5, 2005 11:15 AM PST

Cisco responds to OpenSSL security flaw

Related Stories

Cisco buys Cybertrust security service

November 30, 2005

Cisco's IP vision becomes reality

November 18, 2005

Fixes are in for OpenSSL

March 17, 2004

Cisco Systems on Friday issued a security advisory regarding the use of open-source security software OpenSSL on several of its products. Cisco's advisory follows one issued in October by the OpenSSL Project, which noted that the vulnerabilities could lead to a malicious attacker launching remote code against users' systems.

OpenSSL is an open-source version of secure sockets layer, or SSL, encryption that is used by a number of Web browsers to secure data transmission over the Internet. Cisco's advisory noted that six of its product categories can be affected by the flaws: ASA 5500 and Cisco Pix running 7.x software; CiscoWorks Common Services versions 3.0 and 2.2; Cisco Mainframe Channel Connection PA-4C-E, PA-IC-E, PA-IC-P, CX-CIP2 tn3270 server; Cisco Global Site Selector 4480, 4490 and 4491; Cisco Wireless Control System Software and CiscoIOS-XR.

See more CNET content tagged:
OpenSSL, Cisco Systems Inc., SSL, open source, security

Add a Comment (Log in or register)
Do you know what you are doing?
by Dachi December 5, 2005 11:58 AM PST
This is a man in the middle attack that can force the client to negotiate an SSL 2.0 session rather than an SSL 3.0 session and per the advisory, SSL 2.0 has "cryptographic weaknesses".

First man in the middle attacks are really difficult to perform.

Second, iff they didn't use SSL at all and sent the info in clear text people would not even bother calling it a vuln. But since it is possible to make the client negotiate an SSL 2.0 session instead of 3.0 people want to sensationalize like it is remote level 15 access.

Most people won't bother to look at the details of this release beyond "CISCO ROUTER VULNERABILITY" so all you have really done is give Cisco a black eye when they didn't even deserve it.

I think this article was irresponsible.
Reply to this comment
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (0.71%) 0.17 23.99
Dow Jones Industrials (2.03%) 203.52 10,226.94
S&P 500 (2.22%) 23.78 1,093.08
NASDAQ (1.97%) 41.62 2,154.06
CNET TECH (2.03%) 31.22 1,569.62
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right