Cisco patches security flaws in products#

Cisco Systems has released a security patch to fix vulnerabilities in a number of its products that are at risk of a denial of service attack.

The vulnerabilities are found in a third-party cryptographic library in Cisco IOS, Cisco IOS XR, Cisco PIX and ASA Security Appliances, Cisco Firewall Module and Cisco Unified CallManager products, according to a security advisory issued by Cisco.

The security flaws could allow attackers to send a few small packets through the routers to shut down the network in a DOS attack.

The vulnerabilities can be exploited without a valid username or password, given some of the older Cisco products have the cryptographic library set to default. And while attackers may be able to launch a DOS attack, they are not known to gain access to information that has already been encrypted, Cisco noted.

In its advisory, Cisco includes various links for downloading fixes, as well as offering suggestions for potential workarounds.

Although the vulnerabilities affect a wide range of Cisco products, no exploits have yet surfaced. Related posts:
Microsoft to Seed Vista SP2 to Developers Next Week
Google launches online medical records service
Vista SP1 Available Via Windows Update
OpenID Gets Star Power
Vista SP1 Due on Monday
Microsoft Warns of Office 2003 SP3 Auto-Update

AddThis Social Bookmark Button

Thursday, May 24, 2007 10:12:36 PM (Pacific Standard Time, UTC-08:00) #    Comments [0]  |  Trackback Tracked by:
"Welcome To The Future Of Satellite TV, Bigger, Better, And Stronger Than Ever."... [Trackback]

 

Comments are closed.
    
Search
Google



Sponsors



Subscribe
Tags


Archives
Blog Roll
Submit News To Technophilez