A weakness has been reported in Cisco Adaptive Security Appliance (ASA), which can be exploited by malicious people to disclose sensitive information.
The weakness is caused due to Cisco ASA not correctly sanitising log messages of the "test aaa-server" command before sending them to syslog. This can lead to the disclosure of sensitive information like usernames and passwords.
The error occurs when a user with privilege level 15 or above executes the "test aaa-server" command and logging level 5 (notifications) is activated.
Solution:
Update to 8.0.2.11 for the 8.0 train, 7.2.2.34 for the 7.2 train, 7.1.2.61 for the 7.1 train, and 7.0.7.1 for the 7.0 train.
Thursday, September 6, 2007
Cisco Video Surveillance IP Gateway and Services Platform Authentication Bypass
Some vulnerabilities have been reported in Cisco Video IP Gateway and Services Platform, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
1) The telnet service of the Cisco Video Surveillance IP Gateway video encoders and decoders does not authenticate connecting users. This can be exploited to gain administrative shell access by connecting to the vulnerable service.
2) The Cisco Video Surveillance Services Platform and Integrated Services Platform devices contain a default password for the "sypixx" and "root" accounts. This can be exploited to gain administrative shell access by connecting to the vulnerable service, but requires knowledge of the default password.
The vulnerabilities are reported in:
* Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware version 1.8.1 and earlier
* Cisco Video Surveillance SP/ISP Decoder Software firmware version 1.11.0 and earlier
* Cisco Video Surveillance SP/ISP firmware version 1.23.7 and earlier
1) The telnet service of the Cisco Video Surveillance IP Gateway video encoders and decoders does not authenticate connecting users. This can be exploited to gain administrative shell access by connecting to the vulnerable service.
2) The Cisco Video Surveillance Services Platform and Integrated Services Platform devices contain a default password for the "sypixx" and "root" accounts. This can be exploited to gain administrative shell access by connecting to the vulnerable service, but requires knowledge of the default password.
The vulnerabilities are reported in:
* Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware version 1.8.1 and earlier
* Cisco Video Surveillance SP/ISP Decoder Software firmware version 1.11.0 and earlier
* Cisco Video Surveillance SP/ISP firmware version 1.23.7 and earlier
Cisco Catalyst Content Switching Modules Denial of Service Vulnerabilities
Two vulnerabilities have been reported in the Cisco Catalyst Content Switching Modules (CSM) and Cisco Catalyst Content Switching Module with SSL (CSM-S), which can be exploited by malicious people to cause a DoS (Denial of Service).
1) An unspecified error exists when processing certain TCP packets that were received out of order. This can be exploited to cause a high CPU load or a device reload due to a FPGA4 exception with icp.fatPath length error by sending specially crafted TCP packets to a vulnerable system.
2) An unspecified error exists within the "service termination" option, which can be exploited to cause a PGA4 exception 1 IDLE error under a high network load by sending specially crafted TCP packets to a vulnerable system.
Vulnerability #1 is reported in CSM 4.2 prior to 4.2.3a and CMS-S 2.1prior to 2.1.2a. Vulnerability #2 is reported in CSM 4.2 prior to 4.2.7 and CMS-S 2.1 prior to 2.1.6.
Solution:
Apply updated versions. See vendor advisory for details.
Provided and/or discovered by:
Reported by the vendor.
1) An unspecified error exists when processing certain TCP packets that were received out of order. This can be exploited to cause a high CPU load or a device reload due to a FPGA4 exception with icp.fatPath length error by sending specially crafted TCP packets to a vulnerable system.
2) An unspecified error exists within the "service termination" option, which can be exploited to cause a PGA4 exception 1 IDLE error under a high network load by sending specially crafted TCP packets to a vulnerable system.
Vulnerability #1 is reported in CSM 4.2 prior to 4.2.3a and CMS-S 2.1prior to 2.1.2a. Vulnerability #2 is reported in CSM 4.2 prior to 4.2.7 and CMS-S 2.1 prior to 2.1.6.
Solution:
Apply updated versions. See vendor advisory for details.
Provided and/or discovered by:
Reported by the vendor.
Wednesday, September 5, 2007
Cisco fortifies 802.11n market
Cisco has announced enterprise solutions based on the 802.11n standard. Cisco's backing of the specification could give firms more confidence about deploying the technology in the interim until the standard on which systems are based – 802.11n – is ratified by the Institute of Electrical and Electronics Engineers (IEEE).
Increased speed and performance are two key benefits of the technology Cisco Scotland chief technology officer Richard Moir said, "Organisations deploying 802.11n kit could see a five to ten-fold increase in data transfer speeds and a 2-fold increase in the range at which users could connect to their wireless networks." He added that any changes to the specification would be included in future software updates. "Any changes to the actual 802.11n standard will be addressed", he said.
Butler Group analyst Mark Blowers said that firms could benefit in many ways from the N specification. "Where firms need to have many people wirelessly connected, this technology would be a benefit. There have been reports of 802.11n capabilities eventually leading firms to think about removing wired connectivity at the edge of their networks – 802.11n makes this scenario a lot more feasible" he explained.
The Cisco offering uses its Catalyst 6500-based wireless LAN controller together with the Unified Wireless Network release 4.2 firmware, with 802.11n functions being delivered using new Cisco Aironet 1250 series access points (APs).
The new Aironet 1250 series AP will be available next month priced around £650 + VAT, with Power-over-Ethernet support using Cisco's Catalyst switches scheduled for launch later this year. Cisco's Unified Wireless Network release 4.2 firmware will be available this October.
Increased speed and performance are two key benefits of the technology Cisco Scotland chief technology officer Richard Moir said, "Organisations deploying 802.11n kit could see a five to ten-fold increase in data transfer speeds and a 2-fold increase in the range at which users could connect to their wireless networks." He added that any changes to the specification would be included in future software updates. "Any changes to the actual 802.11n standard will be addressed", he said.
Butler Group analyst Mark Blowers said that firms could benefit in many ways from the N specification. "Where firms need to have many people wirelessly connected, this technology would be a benefit. There have been reports of 802.11n capabilities eventually leading firms to think about removing wired connectivity at the edge of their networks – 802.11n makes this scenario a lot more feasible" he explained.
The Cisco offering uses its Catalyst 6500-based wireless LAN controller together with the Unified Wireless Network release 4.2 firmware, with 802.11n functions being delivered using new Cisco Aironet 1250 series access points (APs).
The new Aironet 1250 series AP will be available next month priced around £650 + VAT, with Power-over-Ethernet support using Cisco's Catalyst switches scheduled for launch later this year. Cisco's Unified Wireless Network release 4.2 firmware will be available this October.
Monday, September 3, 2007
Cisco Turns to Trend Micro for Router Security
Cisco Systems Thursday unveiled plans to add content security services to its routers via an extended partnership with Trend Micro.
The San Jose, Calif.-based networking vendor plans soon to integrate Trend Micro technology into the operating system of its Integrated Services Routers (ISRs), adding services such as content filtering to its family of branch office routers, said Tom Russell, senior director of Cisco's Security Technology Group.
The new offering, which will be available "in the near future," will make it easier for channel partners to build layered security solutions, as the ISR family already supports several integrated security options, Russell said. It will also help push content security out to remote locations, he added.
"You need to have content security at the central site, but you also have to distribute it to all of the points in the network," he said.
Cisco and Cupertino, Calif.-based Trend Micro have been working together since 2004. Trend Micro content security technology is already incorporated into Cisco's Adaptive Security Appliance family of unified threat management wares.
Trend Micro is also a partner in Cisco's Network Admission Control initiative and offers its own Damage Cleanup Services for the Cisco MARS (Mitigation, Analysis and Response System) platform.
The San Jose, Calif.-based networking vendor plans soon to integrate Trend Micro technology into the operating system of its Integrated Services Routers (ISRs), adding services such as content filtering to its family of branch office routers, said Tom Russell, senior director of Cisco's Security Technology Group.
The new offering, which will be available "in the near future," will make it easier for channel partners to build layered security solutions, as the ISR family already supports several integrated security options, Russell said. It will also help push content security out to remote locations, he added.
"You need to have content security at the central site, but you also have to distribute it to all of the points in the network," he said.
Cisco and Cupertino, Calif.-based Trend Micro have been working together since 2004. Trend Micro content security technology is already incorporated into Cisco's Adaptive Security Appliance family of unified threat management wares.
Trend Micro is also a partner in Cisco's Network Admission Control initiative and offers its own Damage Cleanup Services for the Cisco MARS (Mitigation, Analysis and Response System) platform.
Cisco playing network defence
Cisco's six-year-old Self-Defending Network strategy for securing converged networks remains a work in progress: Acquisitions and internal developments are moving it forward even as customers push Cisco to go above and beyond its initial plans.
Cisco spends US$400 million annually - roughly 10 percent of its total R&D budget - on security. The company's aim with SDN is to integrate security into all aspects of a converged data, voice and video network with a focus on secure connectivity, threat defence, and trust and identity management.
In June, Cisco provided its most recent update on SDN after its acquisition of IronPort Systems, a privately held developer of email and web security products. Cisco said IronPort ushered in Version 3.0 of SDN (Version 1.0 involved Cisco's recognition that security is more than point products, like firewalls, VPN concentrators and intrusion-detection systems; Version 2.0 comprised building those capabilities into Cisco products.)
Cisco plans to port IronPort's SenderBase reputation services onto Cisco Adaptive Security Appliance firewalls by the first half of 2008. Cisco also plans to port SenderBase to other key security or routing platforms, such as the Integrated Services Routers and Mitigation Analysis and Response System. Integration with Cisco and third party network admission control (NAC) products also is expected.
"If they can now get email security, Web security - basically all the secure messaging technologies - into that mix they've got a bigger story," says Charlotte Dunlap, senior analyst of enterprise security at Current Analysis.
Dunlap is keeping an eye on how Cisco might take advantage of an existing relationship between IronPort and Vontu, a developer of software that analyzes content and authorizes user access at endpoints to protect against data leakage.
"I'd really like to hear their data-leakage story," says Dunlap, who compares Cisco's purchase of IronPort to Secure Computing's acquisition of CipherTrust last year. "[IronPort does not offer] the level of depth that the data-leakage prevention providers do."
Cisco intends to maintain IronPort's ties to Vontu and exploit the relationship for inclusion in the SDN architecture, according to Jeff Platon, vice president of security marketing at Cisco.
"I think of that as a part of the solution but I do see a variety of other parts of the portfolio that are also being enhanced to be able to participate in a more comprehensive data-leakage solution," Platon says. "It's a tough problem -- you can't just rely on one methodology."
An announcement last week by Cisco and Intel might help. Intel enhanced its vPro processor technology with a Cisco-certified "embedded trust agent" that offers Cisco customers the ability to manage systems without lowering the security on IEEE 802.1x networks and Cisco SDN products.
Nielsen says PG&E hasn't been briefed yet on Cisco's road map for that. But where SDN currently fits is in spots where PG&E is installing new Cisco infrastructure.
"Where we've had problems is where we have legacy systems," Nielsen says. "If a company buys into the Cisco solution and they buy all of the pieces, it works great; but you've got to have all of the pieces there. You can't do clean access NAC on a Catalyst 1900 switch that was built six or 10 years ago; it just doesn't work."
Nielsen notes that this issue is industrywide, not Cisco-specific.
Cisco spends US$400 million annually - roughly 10 percent of its total R&D budget - on security. The company's aim with SDN is to integrate security into all aspects of a converged data, voice and video network with a focus on secure connectivity, threat defence, and trust and identity management.
In June, Cisco provided its most recent update on SDN after its acquisition of IronPort Systems, a privately held developer of email and web security products. Cisco said IronPort ushered in Version 3.0 of SDN (Version 1.0 involved Cisco's recognition that security is more than point products, like firewalls, VPN concentrators and intrusion-detection systems; Version 2.0 comprised building those capabilities into Cisco products.)
Cisco plans to port IronPort's SenderBase reputation services onto Cisco Adaptive Security Appliance firewalls by the first half of 2008. Cisco also plans to port SenderBase to other key security or routing platforms, such as the Integrated Services Routers and Mitigation Analysis and Response System. Integration with Cisco and third party network admission control (NAC) products also is expected.
"If they can now get email security, Web security - basically all the secure messaging technologies - into that mix they've got a bigger story," says Charlotte Dunlap, senior analyst of enterprise security at Current Analysis.
Dunlap is keeping an eye on how Cisco might take advantage of an existing relationship between IronPort and Vontu, a developer of software that analyzes content and authorizes user access at endpoints to protect against data leakage.
"I'd really like to hear their data-leakage story," says Dunlap, who compares Cisco's purchase of IronPort to Secure Computing's acquisition of CipherTrust last year. "[IronPort does not offer] the level of depth that the data-leakage prevention providers do."
Cisco intends to maintain IronPort's ties to Vontu and exploit the relationship for inclusion in the SDN architecture, according to Jeff Platon, vice president of security marketing at Cisco.
"I think of that as a part of the solution but I do see a variety of other parts of the portfolio that are also being enhanced to be able to participate in a more comprehensive data-leakage solution," Platon says. "It's a tough problem -- you can't just rely on one methodology."
An announcement last week by Cisco and Intel might help. Intel enhanced its vPro processor technology with a Cisco-certified "embedded trust agent" that offers Cisco customers the ability to manage systems without lowering the security on IEEE 802.1x networks and Cisco SDN products.
Nielsen says PG&E hasn't been briefed yet on Cisco's road map for that. But where SDN currently fits is in spots where PG&E is installing new Cisco infrastructure.
"Where we've had problems is where we have legacy systems," Nielsen says. "If a company buys into the Cisco solution and they buy all of the pieces, it works great; but you've got to have all of the pieces there. You can't do clean access NAC on a Catalyst 1900 switch that was built six or 10 years ago; it just doesn't work."
Nielsen notes that this issue is industrywide, not Cisco-specific.
Mobile workers don't care about security
Many remote workers are uninterested in security, according to a new study by Cisco. It found that as companies increase workers' usage of laptops and smartphones, the security risks increase as a result of unsafe and sometimes reckless end-user behaviour.
The survey, carried out in conjunction with the US National Cyber Security Alliance (NCSA), questioned 700 mobile employees based in the US, the UK, Germany, China, India, South Korea, and Singapore.
Researchers found that almost three of every four (73%) mobile users claimed that they are not always aware of security threats and best practices when working remotely.
Although many said they are aware "sometimes", more than a quarter (28%) admitted that they "hardly ever" consider security risks and proper behaviour.
When asked why they were lax in their security behaviour, many mobile users offered reasons such as, "I am in a hurry", "I am busy and need to get work done," and "it is IT's job, not mine".
Almost half (44%) of all mobile users surveyed said they open emails and attachments from unknown or suspicious sources.
In the UK, China and India, more than half of users admitted to this behaviour. More than three quarters (76%) said it is more difficult to identify suspicious emails and files on PDAs and smartphones than on laptops, because the screens are much smaller.
With recent research from Korn/Ferry International revealing that, globally, 81% of executives are constantly connected via mobile devices, Cisco says the survey's findings are a cause for concern.
One of the issues contributing to a lack of security when the workforce becomes mobile is the end-user perception that corporate mobile devices are also personal devices and that there is little risk involved in some practices.
Fred Kost, Cisco security adviser, said: "Mobile devices have real access to real data. The perception is that it's a personal device – 'I'm on my device.' "
Mobile workers polled said they often use unauthorised wireless connections. Either hijacking a neighbour's wireless network connection or an unauthorised connection in a public place, one third of mobile users said they use unauthorised wireless. Such activity is illegal in the UK.
China had the most extreme cases, with 54% saying they've used an unauthorised wireless network.
Ron Teixeira, executive director of NCSA, said: “While this study shows mobility provides businesses with new risks, so do other internet services and new technologies. Mobility and the internet can be used securely and safely if businesses institute a culture of security within their workforce by providing their employees with continuous cyber security awareness and education programs.”
The survey, carried out in conjunction with the US National Cyber Security Alliance (NCSA), questioned 700 mobile employees based in the US, the UK, Germany, China, India, South Korea, and Singapore.
Researchers found that almost three of every four (73%) mobile users claimed that they are not always aware of security threats and best practices when working remotely.
Although many said they are aware "sometimes", more than a quarter (28%) admitted that they "hardly ever" consider security risks and proper behaviour.
When asked why they were lax in their security behaviour, many mobile users offered reasons such as, "I am in a hurry", "I am busy and need to get work done," and "it is IT's job, not mine".
Almost half (44%) of all mobile users surveyed said they open emails and attachments from unknown or suspicious sources.
In the UK, China and India, more than half of users admitted to this behaviour. More than three quarters (76%) said it is more difficult to identify suspicious emails and files on PDAs and smartphones than on laptops, because the screens are much smaller.
With recent research from Korn/Ferry International revealing that, globally, 81% of executives are constantly connected via mobile devices, Cisco says the survey's findings are a cause for concern.
One of the issues contributing to a lack of security when the workforce becomes mobile is the end-user perception that corporate mobile devices are also personal devices and that there is little risk involved in some practices.
Fred Kost, Cisco security adviser, said: "Mobile devices have real access to real data. The perception is that it's a personal device – 'I'm on my device.' "
Mobile workers polled said they often use unauthorised wireless connections. Either hijacking a neighbour's wireless network connection or an unauthorised connection in a public place, one third of mobile users said they use unauthorised wireless. Such activity is illegal in the UK.
China had the most extreme cases, with 54% saying they've used an unauthorised wireless network.
Ron Teixeira, executive director of NCSA, said: “While this study shows mobility provides businesses with new risks, so do other internet services and new technologies. Mobility and the internet can be used securely and safely if businesses institute a culture of security within their workforce by providing their employees with continuous cyber security awareness and education programs.”
Subscribe to:
Posts (Atom)