Cisco warns of NetFlow appliance vulnerability

Cisco NetFlow appliances typically sit in campus and data center locations and monitor high-throughput Gigabit Ethernet networks.

cisco-warns-of-netflow-appliance-vulnerability
Thinkstock

Cisco today issued a security warning about a potential vulnerability in its NetFlow traffic monitoring device that could cause the system to lock-up.

+More on Network World: Cisco tries to squash Smart Install security abuse+

Specifically, Cisco wrote: “A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, causing a denial of service (DoS) condition. The vulnerability is due to incomplete validation of SCTP packets being monitored on the NGA data ports. An attacker could exploit this vulnerability by sending malformed SCTP packets on a network that is monitored by an NGA data port. SCTP packets addressed to the IP address of the NGA itself will not trigger this vulnerability. An exploit could allow the attacker to cause the appliance to become unresponsive or reload, causing a DoS condition. User interaction could be needed to recover the device using the reboot command from the CLI.”

Cisco said the vulnerability, which it rated as High, affects NGA models 3140, 3240 and 3340 which typically sit in campus and data center locations and monitor high-throughput Gigabit Ethernet networks.

data sheet c78 720958 0 Cisco/Cisco NetFlow Generation Appliance 3340

“The appliances can be deployed at key observation points such as the server access layer, fabric path domains, and Internet exchange points. Visibility is dramatically amplified when NGA is connected to multiple network devices, allowing Layer 2 and Layer 3 flows to be analyzed hop by hop, essential for security, capacity planning, and troubleshooting,” Cisco said of the devices.

+More on Network World: HPE joins Cisco, Juniper with faulty clock technology problem+

Cisco said it has released software that address this vulnerability.

 Check out these other hot stories:

Cisco Jasper grows Internet of Things reach, breadth

Cisco tries to squash Smart Install security abuse

Space X to zoom two citizen astronauts to the moon

Verizon and Cisco team to bring 5G network pilot program to the masses

IBM, Vermont Electric spawn intelligent energy software company

11 low-tech, decidedly cool cars

Ethernet 2.5GBASE-T and 5GBASE-T grows, testing on tap from UNH lab

IRS Dirty Dozen: Phishing, phone cons and identity theft lead scam list for 2017

Join the Network World communities on Facebook and LinkedIn to comment on topics that are top of mind.
Must read: 10 new UI features coming to Windows 10