Protecting Cisco routers from the IPv6 flaw

Opinion
Aug 8, 20052 mins

* Dr. Internet columnist Steve Blass advises a reader on how to protect Cisco routers

Is it true that attack software for exploiting Cisco routers was publicly released at a recent hacker conference?

No exploit software was publicly released. A recent conference presentation http://www.networkworld.com/news/2005/072805-cisco-black-hat.html described how Cisco IOS might be compromised by the same sort of buffer overflow problems that cause trouble in other operating systems, and a current IOS vulnerability was discussed.

Cisco released an advisory addressing a denial-of-service vulnerability https://www.cisco.com/en/US/products/products_security_advisory09186a00804d82c9.shtml on July 29 affecting “all Cisco devices running any unfixed version of Cisco IOS or Cisco IOS XR code that supports, and is configured for, IPv6.”

Devices running Cisco IOS should be upgraded to a version in which this vulnerability has been fixed.

If you aren’t using IPv6 in your network, you can protect your routers by ensuring that IPv6 is not configured. On a router that is configured for IPv6, do this by issuing the command “no ipv6 enable” and “no ipv6 address” on each interface.

Cisco is providing upgraded software for all customers. Those with service contracts should obtain upgraded software through regular channels. Cisco customers without service contracts should contact the Cisco Technical Assistance Center and be ready to provide the serial number for the routers to be upgraded, along with the URL of the advisory, to receive a free upgrade.