Cisco fixes holes in its firewall, ASA 5500 and CSA
The bad news is that Cisco today warned customers of multiple holes in its security products. The good news is that it has released patches for all of them. Affected products include he Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 switches and Cisco 7600 routers, Cisco ASA 5500 security appliance and Cisco Security Agent releases 5.1, 5.2 and 6.0 and the Cisco PIX 500.
The FWSM vulnerability may cause a denial of service. The Cisco FWSM may be forced to reload after processing an evil Skinny Client Control Protocol (SCCP) message. The vulnerability exists when SCCP inspection is enabled. It is only triggered by transit traffic not by traffic destined for the device.
Cisco warns that the ASA appliance is plagued with several vulnerabilities, most of which could cause DoS, but one of which actually grants the hacker unauthorized access to the device. According to Cisco, the holes are:
- CP Connection Exhaustion Denial of Service Vulnerability
- Session Initiation Protocol (SIP) Inspection Denial of Service Vulnerabilities
- Skinny Client Control Protocol (SCCP) Inspection Denial of Service Vulnerability
- WebVPN Datagram Transport Layer Security (DTLS) Denial of Service Vulnerability
- Crafted TCP Segment Denial of Service Vulnerability
- Crafted Internet Key Exchange (IKE) Message Denial of Service Vulnerability
- NT LAN Manager version 1 (NTLMv1) Authentication Bypass Vulnerability
Cisco says that these holes are not interdependent and patches are available. The holes also affect the Cisco PIX 500 firewall, but because Cisco stopped supporting that product on July 28, 2009 (in favor of ASA) no software updates are available for it. Cisco has offered some suggested workarounds for PIX users.
The company further warns that it has patched multiple holes in CSA, too. One hole is a SQL injection that allows an attacker to to view and download arbitrary files from the server hosting CSA’s Management Center. An attacker might even be able to manipulate this to change the configuration of the product. Another CSA hole could allow a DoS attack in that a successful attack causes the system hosting the CSA agent to crash.
A long list of products using CSA are affected including Cisco Unified Communications Manger/CallManager, Cisco Unity, Cisco Security Manager, and various voice/convergence products.
Jim Duffy is on vacation. This story was written by Cisco Subnet editor Julie Bort.
More from Cisco Subnet:
Cisco said to be readying major upgrade to CRS-1Cisco shipping 160G Ethernet card for ASR 9000Another analyst sees Cisco UCS deployment delaysIf Cisco buys you, you’re 1 in 100IPv4 Space is Getting Low – Really LowThe scoop on the New TSHOOT Course and ExamWin one of 50 CCNP training books, videos and Cert Kits Win great stuff from Cisco Subnet Like e-mail? Subscribe to the Cisco Alert newsletter.Cisco Subnet RSS feedLike RSS readers? Subscribe to the
Follow all Cisco Subnet bloggers on Twitter.Jim Duffy on TwitterFollow




