Wednesday | 3 December, 2008
Cisco patches authorization feature, VPN platform holes
Angela Gunn 27/01/2006 11:04:30

Cisco Systems has issued patches over the past two days for vulnerabilities in an IOS authorization feature and for weakness that might enable a DDoS (distributed denial of service) attack on certain VPN concentrators.

On Wednesday, the company issued a patch to a number of releases of their Internetwork Operating System, covering a vulnerability that would allow users employing the Tcl (Tool Command Language) exec shell to get around the Authentication, Authorization, and Accounting (AAA) command authorization feature. A user who employed the Tcl exec shell could use that access to execute commands above her or his privilege level.

A second problem exacerbated the danger presented by the first. If a user on an affected system terminates her or his session without leaving the Tcl Shell mode (by using the tclquit command), that shell process remains active and attached to the virtual type terminal VTY or TTY line. When another authenticated user connects to that device over the same line, he or she will have access to the unterminated Tcl Shell process and might be able to bypass the AAA command authorization checking.

The vulnerability affects all Cisco products running Cisco IOS version 12.0T or later, if support for the Tcl functionality is enabled and the AAA command authorization feature is enabled as well. It was discovered by security engineers at COLT Telecom and reported to Cisco's Product Security Incident Response Team (PSIRT).

On Thursday, the company addressed a weakness described earlier this month at the SchmooCon conference. That security hole, which affects Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A, would allow a DDoS attack on an unpatched device. A malicious HTTP packet sent to one of those concentrators could cause it to reload, dropping users' connections as it did so.

Cisco has posted a patch for the problem and advises that workarounds are available as well. According to the company, no known attempt has been made to exploit the security hole.

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Achieving the impossible: Unlimited application scalability

Learn how provide applications with significantly higher throughput and lower latency for data operations while retaining the appropriate levels of data quality with clustered caching. Read on to improve your application scalability now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links