We have relaunched: What's new at ZDNet Asia?

Cisco bug could let hackers control Net traffic

Summary

Cisco Systems and an Internet security watchdog warn of a bug in the networking hardware maker's routers that could allow hackers to disrupt Web traffic or intercept information.

Events

Microsoft MSDN/Developer Event
25 Mar 2010

One Marina Boulevard, Microsoft Singapore

IT Architect Regional Conference Singapore 2010
20 - 21 Apr 2010

Singapore Management University, Singapore

The Internet Show 2010
21-22 Apr 2010

Suntec Singapore

LONDON--Networking hardware maker Cisco Systems and the Computer Emergency Response Team (CERT) Coordination Center have warned of a bug in Cisco routers that could allow hackers to disrupt Internet traffic or intercept sensitive information.

The bug, revealed Thursday, allows an attacker to gain control of any Cisco router running certain operating software. Routers are devices that control how data moves around the Internet. Malicious attackers could stop Internet traffic, intercept information such as passwords and credit card numbers, or redirect traffic from Web sites.

The vulnerability allows a person to take control of the router without authorization. It affects "virtually all" mainstream Cisco routers and switches running Cisco's proprietary operating software, known as IOS.

"This access allows a remote attacker to inspect or change the configuration of the device, effectively allowing complete control," Internet security watchdog CERT wrote in an advisory Thursday.

Cisco said the vulnerability is caused by a flaw in the Web-server embedded in its routers that allow administrators to remotely control the devices via the Internet. As a result, it is possible to bypass authentication and exercise complete control over the router. The vulnerability requires little skill to exploit: an attacker can simply send a crafted URL, and commands will be executed on the router.

Cisco is recommending that these internal Web servers be disabled. The company is providing a software upgrade and a "workaround" to fix the problem, which will be available on its Web site.

Cisco said it has not had any reports of the bug being exploited. The bug originally was reported by independent consumers.

"We've had no reports by customers of active exploitation of these vulnerabilities," a Cisco spokeswoman confirmed in an e-mail interview. "The vulnerabilities have been or are in the process of being fixed, and the security advisories are being shared with customers."

Staff writer Matthew Broersma reported from London.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Transform your business interactions with real-time voice, video and telepresence solutions.
Tech Vendor: Cisco

ZDNet Asia Live

He doesn't care if her shoes are of glass, All he wants to see is a huge rack and nice a*s. Sleeping beauty's not awoken by true ...

20 minutes ago by warlowdavies on One pair of 3D glasses to rule them all

RT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd

EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW

Spoke to EMC COO, Pat Gelsinger, earlier, and here's the account of the interview: http://bit.ly/9etOZW

1 hour 2 minutes ago by kevinzdnetasia on topsy

Asian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia

Asian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08

Experts: social media guidelines good for upcoming Youth Olympic Games, but focus on cooperation, not enforcement. http://bit.ly/d9M0BQ

1 hour 34 minutes ago by zdnetasia on topsy

Asian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08

1 hour 35 minutes ago by kevinzdnetasia on topsy

ZDNet Asia features IBM collaboration roadmap story from LCTY Singapore - http://bit.ly/9CuSbZ #lotusknows

2 hours 29 minutes ago by lotusknows on topsy

Internet Jobs in Malaysia - ZDNet Asia http://bit.ly/d0o8Ce

3 hours 12 minutes ago by jamesmt39 on topsy

[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia

URL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia

Temasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU

URL shorteners slow Web redirection. http://bit.ly/bySnWK

Chinese agencies cry foul over Google. http://bit.ly/by6rwV

Philippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC

Gartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb

all of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...

1 day 30 minutes ago by melvinchia on Web filters mean bad news for business

it is not to good for china.
Proactol

1 day 15 minutes ago by nathonastle on Chinese ad partners beg Google for information

RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

For those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i

HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6

** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...

Very good explanation of JMX

2 days 20 minutes ago by Babith B on Managing applications with JMX

The reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.

2 days 24 minutes ago by lonemavericks on diggs

Another ZTE story....

2 days 26 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G license

We at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.

2 days 59 minutes ago by sarah Jane on Companies' outsourcing spend to increase

I agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...

2 days 30 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV instead

hermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...

2 days 7 minutes ago by ... on Facebook user charged in Malaysia

Password manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...

3 days 8 minutes ago by ohanae on What defaults should random password generators use?

I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.

3 days 42 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stick

Thanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...

3 days 42 minutes ago by Roger Biefer on Manage time accuracy with W32Tm

available in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html

3 days 19 minutes ago by steve on Microsoft coy on apps for Zune HD

How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...

3 days 25 minutes ago by Varun V Nair on What defaults should random password generators use?

Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...

3 days 24 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in Asia

Dear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....

4 days 26 minutes ago by Anonymous on Hot tech jobs in Singapore