Feeds

Cisco 600 routers offer cracker fun

Is it trying to force software upgrades?

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Cisco has advised users to update the software used in its 600 family of routers following the identification of what it admits are multiple security vulnerabilities.

Early versions of the operating system on the routers, which is called CBOS, are vulnerable to no less than four separate problems, Cisco admitted in a security vulnerability e-mailed to users earlier today.

Any router in the Cisco 600 family that is configured to allow Web access can be locked by sending a specific URL. If that doesn't take the fancy of crackers, they could always try sending either a large ICMP ECHO (PING) packet to it or a stream of TCP SYN packets to the router - both of which can be used to mount denial of service attacks, or block services to, the routers in question.

Crackers playing with any of these techniques can be assured they are unlikely to be found out. The fourth defect means invalid login attempts using the router's Web interface are not logged, making tracing them more difficult.

The solution to all these problems is to upgrade from earlier software to either of the following CBOS releases: 2.3.5.015, 2.3.7.002, 2.3.9 and 2.4.1. More information on the issue is available here .

The question arises: why not issue an advisory about each vulnerability, since the root cause of each is quiet different? To answer this we did a little digging.

A check of the securityfocus.com, which logs vulnerabilities reports, reveals that Cisco has recorded 22 vulnerabilities advisories involving its products this year. This is way below the 184 postings recorded by Microsoft but still puts it up there in the Premier League.

Aside from volume there is one striking difference between advisories from Cisco and Microsoft. Microsoft issues patches to correct problems in its products, and if these are serious enough offers to include these in the next service pack. Cisco fixes vulnerabilities by asking users to upgrade software - which it generally makes freely available to customers with suitable contracts.

Whether deliberate or not, over time this policy means Cisco has to support fewer users with older versions of its software and users are moving to software with added features that tie them ever closer to the Great Stan of Routers.

Of course this may be a flight of paranoid speculation (although we can't think of another hardware vendor about whom this argument can be made), but it also makes great business sense. ®

Related Stories

Cisco looks rosy, 3Com peaky

Internet Security Threat Report 2014

More from The Register

next story
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
NASA launches new climate model at SC14
75 days of supercomputing later ...
Yahoo! blames! MONSTER! email! OUTAGE! on! CUT! CABLE! bungle!
Weekend woe for BT as telco struggles to restore service
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
DEATH by COMMENTS: WordPress XSS vuln is BIGGEST for YEARS
Trio of XSS turns attackers into admins
BOFH: WHERE did this 'fax-enabled' printer UPGRADE come from?
Don't worry about that cable, it's part of the config
Cloud unicorns are extinct so DiData cloud mess was YOUR fault
Applications need to be built to handle TITSUP incidents
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.