Cisco releases 12 sets of security patches

By Tom Espiner, ZDNet UK
Friday, September 26, 2008 10:41 AM

Networking giant Cisco has published a raft of security advisories as part of its biannual patch-release schedule.

Eleven of the advisories published on Wednesday cover vulnerabilities in Cisco Internetwork Operating System (IOS), the software used on all Cisco switches and most Cisco routers.

The Cisco IOS vulnerabilities addressed include protocol flaws which cause system crashes and hangs, or leave systems open to denial-of-service attacks.

The remaining advisory addresses flaws in Cisco Unified Communications Manager that could leave systems open to denial-of-service attacks.

Details of the advisories and links to patches can be found on Cisco's security-advisories Web page.

Security company Secunia rated the threats 'moderately critical', as sensitive information could be exposed via some vulnerabilities that could allow remote access to a system.

Security company Symantec placed its 'ThreatCon' at level 2, or 'elevated', as a result of one the vulnerabilities affecting Cisco uBR10012 series devices. When configured for linecard redundancy, Cisco uBR10012 series devices use an SNMP community string of 'private' and allow read/write access, warned Symantec, adding that remote attackers could exploit this vulnerability to gain complete control of affected routers.

In March, Cisco patched a number of vulnerabilities in products at risk from denial-of-service attacks.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web