Cisco warns of flaw in its software

By
Follow google news

Cisco Systems has issued an alert about a flaw in its Internetwork Operating System (IOS) software that could allow an attacker to launch a denial-of-service or execute remote code on Cisco devices.

The flaw affects the Firewall Authentication Proxy for FTP and/or Telnet sessions feature in specific versions of IOS software.


"Cisco IOS software is vulnerable to a denial-of-service and potentially an arbitrary code execution attack when processing the user authentication credentials from an Authentication Proxy Telnet/FTP session," Cisco said in its advisory.

"To exploit this vulnerability an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt."

Cisco said it is unaware of any exploits for the vulnerability.

The company has patches available to fix the flaw and also offered workarounds for it.

Earlier this summer, Cisco was the center of controversy at the Black Hat conference when a researcher, Michael Lynn, gave a presentation that showed how attackers could exploit flaws in Cisco software. Cisco sued Lynn, who agreed to a permanent injunction that prevents him from further disclosing his presentation.

www.cisco.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Queensland gov reveals strategy to harden cyber defences

Queensland gov reveals strategy to harden cyber defences

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

Optus takes $826,000 hit for anti-scam breaches

Optus takes $826,000 hit for anti-scam breaches

Log In

  |  Forgot your password?