Cisco details security vulnerability

Opinion
Nov 15, 20052 mins

* Cisco advisory explains how arbitrary code could be run on Cisco equipment

Cisco earlier this month warned users of several security vulnerabilities in its products, including one that could affect almost all users of IOS.

One of Cisco’s advisories says there is a heap-based overflow vulnerability in the system timers of IOS.

If an attacker causes a router or switch’s memory to corrupt in a heap-based overflow, the device would most often crash and then reload. The attacker could achieve a denial of service this way.

However, it is also possible to overwrite areas of system memory. The system timers could then be used to execute the code from those locations, Cisco’s advisory says.

Cisco’s solution is to put in extra checks to make sure the integrity of the system timers is intact. Cisco recommends getting the software fix from the company, as there are no workarounds. Still, an attacker needs a way in (an “attack vector,” as the advisory calls it) to cause the overflow in the first place.

Network World’s Phil Hochmuth writes that the discovery of the vulnerability sprang from the Black Hat conference this summer, where a researcher disclosed a way to get in and take over a router.

Other Cisco vulnerabilities disclosed recently on the company’s list include one in its wireless LAN gear and another (disclosed just this week) that affects equipment that processes IPSec Internet Key Exchange messages.

Cisco has grown so big and has so much code in its products that vulnerabilities are to be expected. Will it get as bad as it has with Microsoft, where monthly patches are necessary?