Cisco is warning of a security hole in its Cisco Application Control Engine Global Site Selector (GSS) that could lead to a crash of the engine’s DNS service. The crash could happen when processing specific DNS requests, according to Cisco in its security advisory. Cisco has published updates and workarounds to mitigate this vulnerability.
The Cisco GSS platform allows customers to leverage global content deployment across multiple distributed and mirrored data locations, optimizing site selection, improving DNS responsiveness, and ensuring data center availability, according to Cisco.
All versions of GSS system software prior to 3.0(1) are affected by this vulnerability. If the GSS is configured with the optional Cisco Network Registrar (CNR) software, the device is not vulnerable, according to the Cisco advisory.
More Cisco security advisories
More from Cisco Subnet:* Cisco: Consumer business to be worth $10 billion in 5 yearsThree candidates pass Cisco’s network design beta examBillion-dollar financial fraud revealed within Satyam, a Cisco collaboration partnerHow I got sold on FCoEJob Prospects Better for CCxP than CCIE?VoIP is dead? – depends on what you define as VoIP* Under the hood: Cisco unified communicationsCisco News and Review podcast*
*
*
*
*
*
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, training/book giveaways, and more.




