News
News
7/29/2005
02:51 PM
Connect Directly
RSS
E-Mail
50%
50%

Cisco Details IOS Vulnerability Spilled At Black Hat

Even as Cisco admitted to the problems, Symantec warned that the information shared at the conference "increases the threat of exploitation."

The impact of the Black Hat presentation on Cisco continued to spread Friday as Symantec warned customers that the information spilled at the conference "increases the threat of exploitation," and Cisco finally published an advisory alerting its users about the vulnerability leveraged in the exploit demonstration.

Michael Lynn, a researcher for Internet Security Systems (ISS) who resigned from his post to present his findings at the security conference, outlined how new exploitation techniques could be applied to old vulnerabilities to seize control of Cisco routers or render them inoperative. Cisco's hardware plays a dominant role in the Internet's infrastructure, and any mass attack on its routers could cripple the Net.

While it hasn't had a chance to confirm Lynn's claims -- and may never, now that a gag order has been placed on both the Black Hat conference and Lynn from further discussion -- Symantec's alert noted that the disclosure "represents a potentially significant threat against existing infrastructure currently deployed."

Symantec went on to explain that attackers may be able to "more reliably exploit vulnerabilities against Cisco IOS (Internetwork Operating System, the OS that runs Cisco's routers and some of its switches) that may have been thought to be extremely difficult or unreliable."

Some already-uncovered vulnerabilities that were earlier thought to be "low risk" may now to exploitable, Symantec concluded.

It recommended that enterprises do an immediate audit of existing vulnerabilities in their Cisco hardware and apply the associated patches ASAP.

For its part, Cisco was adamant that Lynn's demonstrated exploit technique didn't take advantage of a new vulnerability, but instead was only a new and different angle that could be used on existing flaws. The vulnerability Lynn used, said Cisco, was one discovered and patched in April, although customers were never told why the patches had been issued.

On Friday, Cisco disclosed details of that April vulnerability by issuing a security advisory.

According to the advisory, IOS is vulnerable to a denial-of-service (DoS) attack, and possibly to a much more dangerous exploit that could actually introduce hacker code remotely, via a specially-crafted IPv6 packet.

"Lynn did not disclose a new vulnerability," said Cisco spokesman John Noh. "But this advisory relates to the vulnerability he discussed at Black Hat."

Alfred Huger, vice president of engineering for Symantec’s security response team, confirmed that the vulnerability outlined in the Cisco advisory was the same as the one Lynn used Wednesday during his demonstration.

"They are indeed one and the same," Huger said.

While patches for IOS were issued in April for the bug, Cisco "did not issue an advisory at that time, because we have a very clear set of guidelines for disclosing vulnerabilities and when to issue an advisory," Noh added.

Before Cisco believes an advisory is merited, one of three conditions must be met, said Noh. Those include an available fix or patch, confirmation of an active exploit, or what he called a "heightened sense of public awareness."

"That last one was met with the disclosures at Black Hat," Noh said.

In the advisory, Cisco noted that all its devices -- primarily routers -- which run "any unfixed version of IOS code that supports, and is configured for, IPv6" is vulnerable. An attack, however, relies on a maliciously-crafted IPv6 packet that must be sent from a local network segment. "This vulnerability can not be exploited one or more hops from the IOS device," Cisco said. In other words, the attacker would have to have access to a machine inside the perimeter, possibly a previously-compromised computer or device.

Cisco posted a long list of the fixed versions of IOS that users could migrate to if they haven't already done so, as well as a work-around for those unable to patch. That work-around is disable IPv6 processing on devices when the protocol isn't needed.

Comment  | 
Print  | 
More Insights
IT's Reputation: What the Data Says
IT's Reputation: What the Data Says
InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest September 24, 2014
Start improving branch office support by tapping public and private cloud resources to boost performance, increase worker productivity, and cut costs.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.