Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Cisco IOS flaws found

By Phil Hochmuth and Phl Hochmuth , Network World , 01/31/2005
  • Share/Email
  • Tweet This
  • Comment
  • Print

Cisco last week warned of several vulnerabilities in its IOS software that attackers could use to bring down routers in enterprise and service provider networks.

The three separate software flaws are related to Border Gateway Protocol (BGP), Multi-protocol Label Switching (MPLS) and IPv6. Two of the three bugs present the opportunity for an outside attacker to send a specially crafted packet, which would disrupt the router and cause it to reload. Attackers could use this technique repeatedly to mount a denial-of-service attack on the router.

Cisco has updated software available to fix the IOS problems. The company says it has no reports of any of the three bugs being used in an attack.

The BGP, IPv6 and MPLS vulnerabilities in IOS come a week after an IOS flaw was reported that affects Cisco access routers to support IP telephony and VoIP services.

"IOS has had a number of these problems in the past, and Cisco has quietly fixed them," says Frank Dzubeck, president of consulting firm Communications Network Architects. "They never made a big deal about them, the way Microsoft does. Now the question becomes, is IOS the next Windows in terms of a security problem?"

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed