Skip Links

Cisco fixes TCP denial-of-service bug

Cisco addresses DoS vulnerability in routers and switches

By Jim Duffy, Network World
September 09, 2009 01:48 PM ET
  • Print

Cisco this week issued a patch for a denial-of-service vulnerability that affects multiple products.

The vulnerability allows attackers to manipulate the state of TCP connections, according to a Cisco security advisory released this week. By manipulating the state of a TCP connection, an attacker could force the TCP connection to remain in a long-lived state, possibly indefinitely, the Cisco advisory states.

Review: ASR 1000 ready to replace aging Cisco routers

If enough TCP connections are forced into a long-lived or indefinite state, system resources may be consumed, preventing new TCP connections from being accepted and thus initiating a DoS condition. To exploit these vulnerabilities, an attacker must be able to complete a TCP three-way handshake with a vulnerable system, the advisory states.

The bug was first discovered a year ago by Outpost24, a Swedish provider of network security products.

Affected products include scores of routers and switches running IOS, IOS-XE and CatOS operating systems; Cisco ASA and Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and 8.1 under certain configurations; NX-OS-based products such as the new Nexus 5000 and 7000 swsitches; and Scientific-Atlanta and Linksys products.

In addition to these vulnerabilities, Nexus 5000 switches contain a TCP DoS vulnerability that may result in a system crash, the Cisco advisory states. This vulnerability can be exploited remotely without authentication and without user interaction, and repeated attempts to exploit this vulnerability could result in a sustained DoS condition.

Cisco says it has released free software updates for download from its Web site that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are also available, the company says.

Cisco declined further comment on the situation.

Read more about security in Network World's Security section.

  • Print
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?

Videos

rssRss Feed