Showing posts with label Cisco Security Advisory. Show all posts
Showing posts with label Cisco Security Advisory. Show all posts

Thursday, September 27, 2007

Cisco Catalyst 6500 / Cisco 7600 Series Devices Accessible Loopback Address Weakness

A weakness has been reported in Cisco Catalyst 6500 and Cisco 7600 series devices, which can be exploited by malicious people to bypass certain security restrictions.

The problem is that packets destined for the 127.0.0.0/8 network may be received and processed by e.g. the Supervisor module or Multilayer Switch Feature Card (MSFC). This can be exploited to e.g. bypass existing access control lists.

Successful exploitation requires that systems are running Hybrid Mode (Catalyst OS (CatOS) software on the Supervisor Engine and IOS Software on the MSFC) or Native Mode (IOS Software on both the Supervisor Engine and the MSFC).

The weakness is reported in all software versions on Cisco Catalyst 6500 and Cisco 7600 series prior to 12.2(33)SXH.

Solution:
Update to 12.2(33)SXH.

Provided and/or discovered by:
The vendor credits Lee E. Rian.

Thursday, September 13, 2007

Cisco IOS Regular Expressions Denial of Service

A vulnerability has been reported in Cisco IOS, which can be exploited by malicious, local users to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when handling regular expressions containing repetition operators and pattern recalls. This can be exploited to cause a stack overflow by sending a command with specially crafted regular expressions to the command line interface.

Successful exploitation causes the device to crash and requires a reboot, but requires valid user credentials.

The vulnerability is reported in versions 12.0, 12.1, 12.2, 12.3, and 12.4.

Solution:
Restrict access to trusted people only.

Thursday, September 6, 2007

Cisco Adaptive Security Appliance Password Logging Weakness

A weakness has been reported in Cisco Adaptive Security Appliance (ASA), which can be exploited by malicious people to disclose sensitive information.

The weakness is caused due to Cisco ASA not correctly sanitising log messages of the "test aaa-server" command before sending them to syslog. This can lead to the disclosure of sensitive information like usernames and passwords.

The error occurs when a user with privilege level 15 or above executes the "test aaa-server" command and logging level 5 (notifications) is activated.

Solution:
Update to 8.0.2.11 for the 8.0 train, 7.2.2.34 for the 7.2 train, 7.1.2.61 for the 7.1 train, and 7.0.7.1 for the 7.0 train.

Cisco Video Surveillance IP Gateway and Services Platform Authentication Bypass

Some vulnerabilities have been reported in Cisco Video IP Gateway and Services Platform, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.

1) The telnet service of the Cisco Video Surveillance IP Gateway video encoders and decoders does not authenticate connecting users. This can be exploited to gain administrative shell access by connecting to the vulnerable service.

2) The Cisco Video Surveillance Services Platform and Integrated Services Platform devices contain a default password for the "sypixx" and "root" accounts. This can be exploited to gain administrative shell access by connecting to the vulnerable service, but requires knowledge of the default password.

The vulnerabilities are reported in:

* Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware version 1.8.1 and earlier
* Cisco Video Surveillance SP/ISP Decoder Software firmware version 1.11.0 and earlier
* Cisco Video Surveillance SP/ISP firmware version 1.23.7 and earlier

Cisco Catalyst Content Switching Modules Denial of Service Vulnerabilities

Two vulnerabilities have been reported in the Cisco Catalyst Content Switching Modules (CSM) and Cisco Catalyst Content Switching Module with SSL (CSM-S), which can be exploited by malicious people to cause a DoS (Denial of Service).

1) An unspecified error exists when processing certain TCP packets that were received out of order. This can be exploited to cause a high CPU load or a device reload due to a FPGA4 exception with icp.fatPath length error by sending specially crafted TCP packets to a vulnerable system.

2) An unspecified error exists within the "service termination" option, which can be exploited to cause a PGA4 exception 1 IDLE error under a high network load by sending specially crafted TCP packets to a vulnerable system.

Vulnerability #1 is reported in CSM 4.2 prior to 4.2.3a and CMS-S 2.1prior to 2.1.2a. Vulnerability #2 is reported in CSM 4.2 prior to 4.2.7 and CMS-S 2.1 prior to 2.1.6.

Solution:
Apply updated versions. See vendor advisory for details.

Provided and/or discovered by:
Reported by the vendor.

Monday, September 3, 2007

Mobile workers don't care about security

Many remote workers are uninterested in security, according to a new study by Cisco. It found that as companies increase workers' usage of laptops and smartphones, the security risks increase as a result of unsafe and sometimes reckless end-user behaviour.

The survey, carried out in conjunction with the US National Cyber Security Alliance (NCSA), questioned 700 mobile employees based in the US, the UK, Germany, China, India, South Korea, and Singapore.

Researchers found that almost three of every four (73%) mobile users claimed that they are not always aware of security threats and best practices when working remotely.

Although many said they are aware "sometimes", more than a quarter (28%) admitted that they "hardly ever" consider security risks and proper behaviour.

When asked why they were lax in their security behaviour, many mobile users offered reasons such as, "I am in a hurry", "I am busy and need to get work done," and "it is IT's job, not mine".

Almost half (44%) of all mobile users surveyed said they open emails and attachments from unknown or suspicious sources.

In the UK, China and India, more than half of users admitted to this behaviour. More than three quarters (76%) said it is more difficult to identify suspicious emails and files on PDAs and smartphones than on laptops, because the screens are much smaller.

With recent research from Korn/Ferry International revealing that, globally, 81% of executives are constantly connected via mobile devices, Cisco says the survey's findings are a cause for concern.

One of the issues contributing to a lack of security when the workforce becomes mobile is the end-user perception that corporate mobile devices are also personal devices and that there is little risk involved in some practices.

Fred Kost, Cisco security adviser, said: "Mobile devices have real access to real data. The perception is that it's a personal device – 'I'm on my device.' "

Mobile workers polled said they often use unauthorised wireless connections. Either hijacking a neighbour's wireless network connection or an unauthorised connection in a public place, one third of mobile users said they use unauthorised wireless. Such activity is illegal in the UK.

China had the most extreme cases, with 54% saying they've used an unauthorised wireless network.

Ron Teixeira, executive director of NCSA, said: “While this study shows mobility provides businesses with new risks, so do other internet services and new technologies. Mobility and the internet can be used securely and safely if businesses institute a culture of security within their workforce by providing their employees with continuous cyber security awareness and education programs.”

Wednesday, August 22, 2007

Crash bug blights Cisco IP phones

Cisco has advised users to update the firmware on some of its IP phones following the discovery of two security flaws.

A brace of Session Initiation Protocol (SIP) vulnerabilities in Cisco 7940/7960 IP Phones create the potential for hackers to crash - but not to run exploit code - on vulnerable handsets.

SIP is a signalling protocol for VoIP. The protocol can be used to create two-party, multiparty, or multicast sessions.

Cisco IP Phone 7940/7960 SIP firmware versions prior to 8.7(0) are vulnerable to the denial of service attacks, Cisco warns. Users are advised to update their firmware to version 8.7(0), as explained in its advisory here.

More detail on the vulnerabilities can be found in posts (here and here) to full disclosure mailing lists by the independent security researchers (Radu State, Humberto J Abdelnur, and Olivier Festor) who discovered the bugs.

Monday, August 20, 2007

Cisco IOS Next Hop Resolution Protocol DoS

NHRP is "basically a query-and-reply protocol and all parties through which reply information passes build a 'network knowledge table' that can be used for all subsequent traffic".

A vulnerability in Cisco IOS allows remote denial of service, the following exploit code can be used to test it.

Exploit
Original Advisory

Monday, August 13, 2007

Cisco site blacked out

A Web site blackout yesterday prevented Cisco Systems Inc. customers from retrieving 21 critical patches for about three hours yesterday, shortly after the fixes were posted by the network hardware maker.

Updates for nearly two dozen vulnerabilities in IOS, formerly known as Internetwork Operating System and the controlling software for most Cisco routers and switches, were released around 11 a.m. EDT Wednesday. Cisco.com, however, went dark around 2 p.m. EDT and didn't come back online until about 5 p.m. Today, Cisco blamed "human error" for the site swooning, and added that the severity of the resulting electrical overload prevented the expected redundancies from kicking in.

The 21 patches, deployed in four updates, were posted three hours before the blackout, and would repair IOS against a swath of vulnerabilities, some of which could result in attackers injecting their own code into vulnerable Cisco hardware. Three of the four IOS updates, according to Cisco's advisories, plug holes that attackers can, or might be able to, exploit with remote code.

Internet Storm Center analyst Tom Liston ranked two of the four -- "Secure Copy Authorization Bypass Vulnerability" and "Voice Vulnerabilities in Cisco IOS" -- as especially dangerous, and urged administrators to patch them as soon as possible.

Of the bypass update, Liston said: "[The attacker] needs a log-in, but after that, it's pretty much game-over." The 16 bugs quashed by the voice vulnerabilities update are even scarier, he said. "The others can potentially wait for testing, this [set] can't. Patch now."

Danish vulnerability tracker Secunia, however, rated the bypass bug as "less critical," the second step in its five-mark scoring system, and tagged the voice flaws as "moderately critical," its middle rank.

Thursday, August 9, 2007

Cisco patches serious holes in voice-enabled offerings

Cisco issued four updates that patch a raft of security holes in products running its Internetwork Operating System (IOS). Impacts included sustained denial of service attacks, data leakage and remote execution of code.

The most serious vulnerabilities reside in voice-enabled devices and Cisco Unified Communications Manager, which can allow an attacker to remotely execute malicious code. There are no workarounds for the flaws, which pertain to services such as Session Initiation Protocol, Media Gateway Control Protocol, Signaling protocols H.323, H.254, Real-time Transport Protocol and Facsimile reception.

"This one is bad, as in real bad," Johannes Ullrich, CTO for SANS Internet Storm Center, told The Reg. "I would probably expedite the testing process for that. "The other vulnerabilities, you want to be really careful about testing them and they don't seem to be overly critical."

Vulnerable IOS versions include various flavors of 12.3(4), 12.3(7), 12.3(8), 12.4 Mainline and 12.4T onward. Routers that are configured as SIP Public Switched Telephone Network Gateways and SIP Session Border Controllers are also vulnerable, as is the CAT6000-CMM card.

Other updates addressed a data leakage flaw when using IPv6 routing headers and a weakness in the IOS Next Hop Resolution Protocol that can result in a restart of the device or possible remote code execution.

A fourth patch plugs a hole in some 12.2-based IOS releases when configured to offer Secure Copy server functionality. Those vulnerabilities allow valid users, regardless of privilege level, to transfer files to and from an IOS device. To exploit it, an attacker would have to have access to port 22, which typically is open only on management interfaces.

Nonetheless, Immunity, a company that provides penetration testing tools, plans to add modules to its products that test for the vulnerability, said Kostya Kortchinsky, a senior researcher at the company.

"Anybody can exploit this without any skill in Cisco exploitation," he explained. "It doesn't need any overflow of any kind."

The patches were released the same day Cisco's website was inaccessible for about three hours. A spokeswoman later said the outage was the result of an accident during maintenance that cut off power to a San Jose data center.

Cisco IOS Next Hop Resolution Protocol Buffer Overflow
Cisco IOS IPv6 Routing Header Information Disclosure and Denial of Service
Cisco IOS Secure Copy Security Bypass Vulnerability
Cisco Unified Communications Manager SIP Packet Processing Vulnerability
Cisco Unified MeetingPlace "STPL" and "FTPL" Cross-Site
Scripting

Cisco IOS Voice Service Multiple Protocol Handling Vulnerabilities

Wednesday, July 25, 2007

Cisco warns of bugs in wireless LAN controllers

The vulnerabilities affect Cisco Wireless LAN Controllers, but the company is offering a workaround..

Cisco Systems released a security advisory on Tuesday afternoon to address several vulnerabilities in its Wireless LAN Controllers that could enable hackers to cause a denial-of-service on the affected network.

The flaws lie in the handling of Address Resolution Protocol (ARP) packets. The advisory noted that a unicast ARP request may be flooded on the LAN links between Wireless LAN Controllers in a mobility group.

A vulnerable WLC may mishandle unicast ARP requests from a wireless client, leading to an ARP storm. The bugs affect versions 4.1, 4.0, 3.2, and prior versions of the Wireless LAN Controller software, according to the advisory.

The protocol provides a mapping between a device's IP address and its hardware address on the local network. And the Cisco Wireless LAN Controllers provide real-time communication between lightweight access points and other wireless LAN controllers for centralised system-wide WLAN configuration and management functions, according to Cisco.

As a workaround, Cisco is recommending that operators require all clients to obtain their IP addresses from a DHCP server.

Thursday, July 19, 2007

Cisco Wide Area Application Services Edge Services SYN Flood Denial of Service

Software: Cisco Wide Area Application Services (WAAS)

Description:

A vulnerability has been reported in Cisco Wide Area Application Services (WAAS), which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in Edge Services, which uses CIFS optimisation, when handling packets sent to ports 139/TCP and 445/TCP. This can be exploited to cause a device running WAAS to stop processing all traffic by sending a TCP SYN flood to port 139/TCP or 445/TCP.

Successful exploitation requires that WAAS is configured for Edge Services.

The vulnerability is reported in WAE appliances and the NM-WAE-502 network modules running WAAS versions 4.0.7 or 4.0.9.

Solution:

Update to version 4.0.11.

Thursday, July 12, 2007

Cisco Unified Communications Manager and Presence Server Security Bypass

Description:

Two vulnerabilities have been reported in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Cisco Unified Presence Server (CUPS), which can be exploited by malicious users to bypass certain security restrictions.

The vulnerabilities are caused due to unspecified errors and can be exploited by an unauthorized administrator to e.g. activate and terminate system services or to view SNMP configuration information in a CUCM/CUPS cluster environment.

The vulnerabilities affect the following versions:

- Cisco Unified CallManager 5.0 and Communications Manager 5.1 versions up to and including 5.1(2)
- Cisco Unified Presence Server versions 1.0 to 1.0(3)

Solution:

Apply updates.

Tuesday, June 12, 2007

Multiple Vulnerabilities in Wireless Control System

Cisco Wireless Control System (WCS) contains multiple vulnerabilities which may allow a remote user to:

- access sensitive configuration information about access points managed by WCS
- read from and write to arbitrary files on a WCS system
- log in to a WCS system with a default administrator password
- execute script code in a WCS user's web browser
- access directories which may reveal sensitive WCS configuration information

There are workarounds for several, but not all, of these vulnerabilities. See the Workarounds section for more information. Cisco has made free software available to address these vulnerabilities for affected customers.

This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20060628-wcs.shtml.