Skip Links

Network World

Jim Duffy

Cisco PGW softswitch susceptible to crash, DoS

Advisory spells out vulnerabilities to SIP, MGCP implementations

By Jim Duffy on Wed, 05/12/10 - 10:13pm.

Cisco's PGW 2200 softswitch line is susceptible to multiple vulnerabilities, including system crash and denial of service. The vulnerabilities were disclosed in a Cisco security advisory this week.

The vulnerabilities, nine in all, are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages and each vulnerability is independent of the other, the advisory states. Exploitation of all but one can crash the system, while the other can block creation or acceptance of new TCP connections, creating a DoS situation.

Multiple vulnerabilities exist in the SIP implementation of the softswitches while the MGCP implementation has one, the advisory states.

Cisco says it has released free software updates to address the vulnerabilities. There are no workarounds for them, the advisory states. The glitches were discovered during internal testing, and Cisco says it is not aware of any public announcements or malicious use of them.

More from Cisco Subnet:

Win great stuff from Cisco Subnet
Like e-mail? Subscribe to the Cisco Alert newsletter.

Like RSS readers? Subscribe to the Cisco Subnet RSS feed

Follow all Cisco Subnet bloggers on Twitter.

Follow Jim Duffy on Twitter

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
About The Cisco Connection

The Cisco Subnet blog is written by Network World managing editor Jim Duffy Visit the Cisco Subnet home page daily and while you are there, subscribe to the Cisco Alert e-mail newsletter, which includes news and views generated by the Cisco Subnet community as well as Cisco-related stories on Network World and elsewhere on the Web.

Follow Jim Duffy on Twitter

 

Most Discussed Posts