Cisco router bug threatens Net security

By Matthew Broersma
Monday, July 02, 2001 10:45 AM
Cisco Systems and CERT, the security advisory organization, have warned of a bug in Cisco routers and switches. The glitch could give a hacker the ability to disrupt Internet traffic or intercept sensitive information.

The bug, revealed last Thursday, allows a malicious user to gain control of any Cisco router running IOS software. The bug affects all releases of the software, which controls most of Cisco's products, beginning with version 11.3. The bug affects "virtually all" mainstream Cisco routers and switches running IOS.

The vulnerability requires little skill to exploit: A malicious user can simply send a crafted URL and commands will be executed on the router or switch.

The bug allows an attacker to take control of routers at the highest level--level 15--without authorization. Routers are devices that control how data moves around the Internet; with such unauthorized control, hackers can stop Internet traffic, intercept information such as passwords and credit card numbers, or redirect traffic bound for one Web site to another.

Cisco said that when an HTTP server is enabled and users are authorized from a local database, it is possible for a hacker to bypass authentication and exercise complete control over the router.

The company is recommending that HTTP servers on routers be disabled. The problem can also be sidestepped by using Terminal Access Controller Access Control System (TACACS+) or Radius systems for authentication instead of a local database.

According to Cisco, the crafted URL used to exploit the bug takes the form: http:///level/xx/exec/.... Where xx is a number between 16 and 99.

The same URL will not be effective on every device, depending on the combination of hardware and software releases. But since there are only 84 combinations to try, they could all be tested in a short space of time, Cisco said.

Cisco said it has not had any reports of the bug being exploited. It was originally reported by independent users.

The company said it is providing a software upgrade to fix the problem, which will be available on its Web site .


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Time to map out

Blog thumbnail

Before anything else, let me devote a few words to the fallen journalists and other victims of the brutal massacre that occurred last week in the southern province of Maguindanao...... by Melvin G. Calimag

Read more »

Tags

  1. acquisition
  2. acquisitions
  3. ceo
  4. china
  5. financial
  6. google inc.
  7. green it
  8. ibm corp.
  9. india
  10. industry
  11. information technology
  12. it outsourcing
  13. job
  14. microsoft corp.
  15. network
  16. outsourcing
  17. revenue
  18. singapore
  19. software
  20. u.s.