Cisco warns of flaw in its software

By
Follow google news

Cisco Systems has issued an alert about a flaw in its Internetwork Operating System (IOS) software that could allow an attacker to launch a denial-of-service or execute remote code on Cisco devices.

The flaw affects the Firewall Authentication Proxy for FTP and/or Telnet sessions feature in specific versions of IOS software.


"Cisco IOS software is vulnerable to a denial-of-service and potentially an arbitrary code execution attack when processing the user authentication credentials from an Authentication Proxy Telnet/FTP session," Cisco said in its advisory.

"To exploit this vulnerability an attacker must first complete a TCP connection to the IOS device running affected software and receive an auth-proxy authentication prompt."

Cisco said it is unaware of any exploits for the vulnerability.

The company has patches available to fix the flaw and also offered workarounds for it.

Earlier this summer, Cisco was the center of controversy at the Black Hat conference when a researcher, Michael Lynn, gave a presentation that showed how attackers could exploit flaws in Cisco software. Cisco sued Lynn, who agreed to a permanent injunction that prevents him from further disclosing his presentation.

www.cisco.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

ASD to retire Essential Eight cyber security framework within next two years

ASD to retire Essential Eight cyber security framework within next two years

ASD draws a hard line on developers lacking security skills

ASD draws a hard line on developers lacking security skills

Fake IT worker threat spreads outside tech sector in Australia

Fake IT worker threat spreads outside tech sector in Australia

NAB builds integrated ops hub for threat intelligence

NAB builds integrated ops hub for threat intelligence

Log In

  |  Forgot your password?