Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Netscape Founder Seeks to Fund Next Gates, Jobs
Symantec desktop security software boasts reputation analysis
Rackspace to issue as much as $3.5M in customer credits after outage
NetApp's buy of Data Domain moves closer, even as EMC raises offer to $2.1B
Survey: IT pros are optimistic about bigger budgets next year
American Express inks outsourcing deal with HP EDS
Cloud interoperability remains wispy, but progress being made
Ex-Bay Networks CEO: Nortel's enterprise group could do well on its own
The tech industry's most baffling buzzwords: A brief guide
Net neutrality advocates score big win with broadband stimulus rules
Broadband subsidy: too much money, but mostly well targeted
Google freebie puts school system in the Apps cloud
Security guard charged with hacking hospital systems
Cisco looks to accelerate virtualization deployments
Apple patching serious SMS vulnerability on iPhone
/

Software flaw opens Cisco devices to hackers

Related linksToday's breaking news
Send to a friendFeedback


A flaw in Cisco Internetwork Operating System could allow hackers to gain full control over virtually all Cisco routers and switches using the software, Cisco said in a security advisory issued Thursday.

The Computer Emergency Response Team at Carnegie Mellon University in Pittsburgh also warned of the vulnerability later Thursday.

A vulnerability exists in the HTTP server component of the IOS software. By requesting a particular URL from the server, a malicious user can bypass the authentication controls and execute commands on the device at the highest privilege level, Level 15, Cisco said.

Only devices with the HTTP server software enabled and with user names and passwords stored on the device - the local authentication database - are vulnerable, the company said. The issue affects all releases of Cisco IOS software starting with Release 11.3.

Once a hacker has gained access he could redirect data traffic, allowing him to intercept or modify the data. Additionally he could change or delete the device configuration, effectively disabling the router or switch until an engineer reprograms it, said Cisco Security and Network Management Systems Engineer Tames van der Does.

The HTTP server in IOS is used for remote management of the router or switch. However, a configuration with the HTTP server enabled and the local database for authentication used is a rarity, according to Van der Does.

"Most engineers use Telnet to access their network hardware and have a central Terminal Access Controller Access Control System or Radius server to authenticate users for all their networking hardware," he said, adding that the HTTP server is switched off by default on Cisco hardware.

Routers and switches direct network traffic and are used to interconnect computer networks. Cisco's hardware is used around the world by small and large businesses as well as home users.

Cisco has made software fixes available to plug the hole.

The IDG News Service is a Network World affiliate.

Related Links

 
NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.