jim_duffy
Managing Editor

Cisco IOS FTP Server open to attacks

Analysis
May 9, 20071 min

Cisco is warning of several holes in its IOS FTP Server feature that could lead to denial of service attacks, improper vertication of user credentials and the ability to retrieve or write any file from the device filesystem.

Cisco’s advisory notes:

The IOS FTP Server is an optional service that is disabled by default. Devices that are not specifically configured to enable the IOS FTP Server service are unaffected by these vulnerabilities.

This vulnerability does not apply to the IOS FTP Client feature.

The full advisory is here.