tgreene
Executive Editor

Cisco firewall vulnerability could compromise the VPN

Opinion
Aug 8, 20062 mins

* Watch for Cisco fixes in the next days, weeks

The Cisco PIX firewall vulnerability highlighted at last week’s Black Hat conference is of concern to anyone using the firewall’s capability to establish VPNs between sites.

The whole point of the VPN is to create a secure site-to-site IPSec connection that passes through the firewall, creating a package that protects network resources at both sites. This firewall-VPN combination is pretty much standard among VPN appliance vendors because tight integration is key to successful protection.

With the firewall compromised, it doesn’t much matter that the VPN is there to allow trusted traffic. There is no longer a barn door and attackers are pretty much invited to take all the horses.

So anyone using one of these firewalls needs to pay attention to Cisco’s security people over the next days and weeks and install whatever patches they come up with. This is a little alarming given on the description of the exploit by the person who developed it.

“You can open up whatever port you want… and access internal servers from the outside,” says Hendrik Scholz, a developer with Freenet Cityline. “It’s really easy to do and we’re talking to Cisco about how to get it fixed.” It’s really easy. Yikes.

By the way, Scholz did this the right way. He warned about the exploit so people using the PIX are on guard but didn’t publish the exploit. Instead, he did the responsible thing and shared it only with Cisco, which can now make it right.