jim_duffy
Managing Editor

Cisco security products open to attack

Analysis
May 3, 20071 min

Cisco’s security tools are vulnerable to LDAP authentication bypasses and denial of service attacks, warns the vendor. Cisco says there are multiple vulnerabilities in its Adaptive Security Appliance and PIX gear, and has posted up fixes.

According to Cisco’s security advisory: “The Lightweight Directory Access Protocol (LDAP) authentication bypass vulnerabilities are caused by a specific processing path followed when the device is setup to use a Lightweight Directory Access Protocol (LDAP) authentication server. These vulnerabilities may allow unauthenticated users to access either the internal network or the device itself.

“The two DoS vulnerabilities may be triggered when devices are terminating Virtual Private Networks (VPN). These denial of service vulnerabilities may allow an attacker to disconnect VPN users, prevent new connections, or prevent the device from transmitting traffic.”