Cisco Warns of Flaw in Firewall Products
An alert from Cisco Systems Inc. describes an unintentional password modification vulnerability in multiple firewall products that could be exploited to change passwords without user interaction and allow “unauthorized users to gain access to a device that has been reloaded after passwords in its startup configuration have been changed. Authorized users can be locked out and lose the ability to manage the affected device.”
The flaw affects Cisco PIX 500 Series Security Appliances, Cisco ASA 5500 Series Adaptive Security Appliances and Firewall Service Module (FWSM) for Cisco Catalyst 6500 switches and Cisco 7600 Series Routers running affected versions of the software.
Cisco has issued software to address this vulnerability. A second alert from Cisco describes a pair of flaws in Cisco VPN 3000 series concentrators with FTP file management enabled that could be exploited to execute some FTP commands and delete files. Cisco has issued free software to address these two flaws and also made workarounds available.
http://www.cisco.com/en/US/products/products_security_advisory09186a00807183b0.shtml
http://www.cisco.com/en/US/products/products_security_advisory09186a0080718330.shtml
September 9th, 2006 at 5:46 pm
Interesting site! very informative… thanks!
September 10th, 2006 at 5:47 am
This is very interesting info. Thank you very much for sharing.
September 10th, 2006 at 2:39 pm
thanks for mentioning this
September 10th, 2006 at 5:37 pm
Very nice site!
September 10th, 2006 at 8:40 pm
Very nice site indeed!