jim_duffy
Managing Editor

Cisco IOS vulnerable to malformed SSL packets

Analysis
May 23, 20071 min

Cisco is warning that its IOS devices may crash while processing malformed SSL packets.

According to its security advisory:

In order to trigger these vulnerabilities, a malicious client must send malformed packets during the SSL protocol exchange with the vulnerable device.

Successful repeated exploitation of any of these vulnerabilities may lead to a sustained Denial-of-Service (DoS); however, vulnerabilities are not known to compromise either the confidentiality or integrity of the data or the device. These vulnerabilities are not believed to allow an attacker to decrypt any previously encrypted information.

Software fixes and workaround are available here.