A couple of new PIX/ASA and AVS vulnerabilities

Analysis
Jan 23, 20082 mins

A quick drive by blog post, but Cisco released two new security advisories today.

The first is for PIX/ASA’s running versions prior to 7.2(3)006 or 8.0(3). The TTL decrement feature which was first introduced in 7.2(2) and is disabled by default is at the root of the vulnerability. A successful exploit results in the reload of the device, which could obviously be a denial of service. You can workaround the vulnerability by disabiling the TTL decrement feature (again, it’s disabled by default) or by obtaining a software fix from Cisco. More details can be located at https://www.cisco.com/en/US/products/products_security_advisory09186a008093942e.shtml#@ID

The second one affects the Cisco Application Velocity System (AVS) prior to software version AVS 5.1.0. These versions didn’t prompt for or require that the default credentials be changed, which in turn would allow someone using default credentials to access the system. While I’m not sure this one is really a Cisco “bug” in as much as it’s more a “we should have been requiring the change”, you can workaround this by making sure you have changed the default passwords (which everyone should always do anyway) or obtain the software update from Cisco. More details can be located at https://www.cisco.com/en/US/products/products_security_advisory09186a0080939431.shtml#@ID

Wes

http://www.netiq.com