News

Cisco Warns Of Multiple IOS Vulnerabilities

Sharon Gaudin

Cisco Systems announced on Tuesday that there are several vulnerabilities in the Intrusion Prevention System feature set of its Cisco IOS.

Cisco Systems announced on Tuesday that there are several vulnerabilities in the Intrusion Prevention System (IPS) feature set of its Internetwork Operating System (IOS).

Fragmented IP packets may be used to evade signature inspection, according to a warning on Cisco's Web site. It also warned that the IPS signatures using the regular expression feature of the Atomic.TCP signature engine may cause a router to crash, resulting in a denial of service.


More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Cisco's IOS is software used in many of its routers and network switches.

Four versions of Cisco IOS are vulnerable to the fragmented packet evasion vulnerability: Version 12.4, 12.4T, 12.4XE, and at least one release of 12.3T. Many of the IOS version releases are vulnerable to the Atomic.TCP regular expression denial of service flaw.

An alert on the SANS Institute's Internet Storm Center recommends an upgrade of the IOS version.

Related Reading


Informationweek Discussions

Start the Discussion


InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links