Cisco releases security alert after Black Hat drama

By
Follow google news

Cisco Systems on Friday released a security alert about a vulnerability in its router software, two days after taking legal action against a researcher who exposed the flaw at the Black Hat conference.

Cisco said its Internetwork Operating System (IOS) Software is vulnerable to a denial-of-service attack and possibly "an arbitrary code execution attack from a specially crafted IPv6 packet" sent from a local network segment. IPv6 is the next-generation Internet Protocol.


The company said it has made free software available to its customers to address the vulnerability.

Earlier in the week, Cisco sued researcher Michael Lynn the same day he gave a presentation at the Black Hat conference in Las Vegas that showed how attackers could exploit flaws in IOS to take over routers.

Lynn went ahead with the presentation after quitting his job at Internet Security Systems, which had decided to cancel his talk. ISS and Cisco said his findings required more research before going public. Lynn said afterwards that it was critical that people understand that vulnerabilities could be exploited on the network infrastructure.

Lynn and Cisco reached a settlement Thursday, under which agreed to not further disclose the information in his presentation plus other conditions.

In its advisory, Cisco said the vulnerability affects all Cisco devices running any unfixed version of IOS code that supports and is configured for IPv6.

www.cisco.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Euro cops take down cybercrime network with 49 million fake accounts

Euro cops take down cybercrime network with 49 million fake accounts

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Home Affairs streamlines risk vetting for gov tech suppliers

Home Affairs streamlines risk vetting for gov tech suppliers

Log In

  |  Forgot your password?