jim_duffy
Managing Editor

Cisco IronPort flaw could expose contents of secure e-mails

Analysis
Jan 15, 20092 mins

Cisco released two security advisories: one announcing two vulnerabilities in its IronPort PXE Encryption product that could expose contents of secure e-maill messages, and the other referring to a TCP vulnerability affecting its ONS 15xxx edge optical platforms.

Cisco is reporting of two security holes in IronPort PXE Encryption that could allow hackers to view the contents of secure e-mail messages. Free software fixes are available and there are no workarounds.

Cisco says a reload of the device control card of two ONS products could occur when processing TCP traffic streams. The affected products are Cisco ONS 15300 series and 15454 Optical Transport Platforms, the Cisco ONS 15454 SDH Multiservice Platform, and the Cisco ONS 15600 Multiservice Switching Platform A fix is available and Cisco says there is no workarounds to mitigate the vulnerability.

Cisco also released two security responses, one involving MD5 collisions in certificates issued by vulnerable certificate authorities, and the other involving two separate IOS HTTP cross-site scripting (XSS) vulnerabilities.

More Cisco security advisories

More Cisco security responses

More from Cisco Subnet:* Podcast: Cisco aims to ease 11n deployment with new AP* Cisco to launch unified-communications-as-a-service?Nortel employee severance payments frozen by bankruptcyIs your software multicore ready?Changes to CCIE written and lab examsWhy are you going for the CCIE (poll)?Configuration management on a budget* Under the hood: Cisco unified communicationsCisco News and Review podcast Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, training/book giveaways, and more.

*

*

*

*

*

*

Go to