CertCities.com -- The Ultimate Site for Certified IT Professionals
Listen, See, Win! Register for a Free Tech Library Webcast Share share | bookmark | e-mail
  Microsoft®
  Cisco®
  Security
  Oracle®
  A+/Network+"
  Linux/Unix
  More Certs
  Newsletters
  Salary Surveys
  Forums
  News
  Exam Reviews
  Tips
  Columns
  Features
  PopQuiz
  RSS Feeds
  Press Releases
  Contributors
  About Us
  Search
 

Advanced Search
  Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:



 
 
...Home ... Editorial ... News ..News Story Tuesday: December 28, 2010


Range of Cisco Products Vulnerable


5/21/2007 -- Cisco Systems Inc. last week warned of a vulnerability that affects its Adaptive Security Appliance (ASA) and PIX Security Appliance, as well as its Cisco Intrusion Prevention System (IPS) and Cisco IOS with Firewall/IPS feature sets.

This flaw is actually common to many IPSes and firewalls. It was first disclosed in a vulnerability note published by US-CERT, which indicated that it's possible for an attacker to camouflage an HTTP-based attack by encoding URLs using half-width or full-width Unicode characters. Firewalls and IPSes perform deep packet inspection on HTTP traffic, to be sure, but many don't properly decode URLs that are encoded by means of this method. As a result, US-CERT warned, they might fail to recognize potentially harmful URLs.

In Cisco's case, its affected products can decode full-width and half-width Unicode characters -- although certain characters aren't decoded properly, Cisco warned.

The good news, Cisco says, is that none of its affected products can actually be compromised by such an attack; such products might, however, fail in their primary purpose -- namely, to detect attacks (in this case, an HTTP-based attack) against infrastructure assets.

That's the good news. The bad news is that Cisco hasn't yet developed a fix to address this flaw. Software updates are in the works and will be made available to customers once they're ready, Cisco says. --Stephen Swoyer



Current CertCities.com user Comments for “Range of Cisco Products Vulnerable

There are no comments yet. Post one now.

Your comment about: “Range of Cisco Products Vulnerable”
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comment:
   

-- advertisement (story continued below) --

top