* Advisories indicate just how susceptible routers and router software are to attack
endif; ?>Cisco has issued yet another vulnerability alert for its IOS software.
This one involves a firewall authentication proxy feature for FTP and Telnet sessions in specific versions of the Cisco software. The feature is vulnerable to a remotely-exploitable buffer overflow condition, according to a Cisco Security Advisory issued last week.
Cisco issues a few security advisories a month. Observers commend Cisco for its usually proactive communication, yet the advisories indicate just how susceptible routers and router software are to attack.
In one recent episode, however, Cisco attempted to conceal notification of a vulnerability. At the Black Hat security conference in July, Cisco and Internet Security Systems threatened legal action against a security researcher who planned to deliver a presentation on some unpublished vulnerabilities found in Cisco routers and IOS software.
Cisco even went to such lengths as to tear the presentation materials out of conference handbooks. The researcher, Michael Lynn, delivered the presentation anyway, and later reached a legal settlement with Cisco and ISS enjoining him from disseminating his findings.
Cisco subsequently issued a security advisory related to Lynn’s presentation.
Last week’s advisory stated that the firewall authentication proxy feature for FTP and Telnet in IOS Versions 12.2ZH and 12.2ZL, 12.3, 12.3T, 12.4 and 12.4T is vulnerable to a denial-of-service and potentially an arbitrary code execution attack when processing the user authentication credentials from an authentication proxy Telnet/FTP session. To exploit this vulnerability, an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt, the advisory states.
Cisco has made free software available to address it and published workarounds in the advisory to mitigate its effects.




