Cisco Warns of Flaw in Firewall Products

An alert from Cisco Systems Inc. describes an unintentional password modification vulnerability in multiple firewall products that could be exploited to change passwords without user interaction and allow “unauthorized users to gain access to a device that has been reloaded after passwords in its startup configuration have been changed. Authorized users can be locked out and lose the ability to manage the affected device.”  

The flaw affects Cisco PIX 500 Series Security Appliances, Cisco ASA 5500 Series Adaptive Security Appliances and Firewall Service Module (FWSM) for Cisco Catalyst 6500 switches and Cisco 7600 Series Routers running affected versions of the software.

Cisco has issued software to address this vulnerability.  A second alert from Cisco describes a pair of flaws in Cisco VPN 3000 series concentrators with FTP file management enabled that could be exploited to execute some FTP commands and delete files.  Cisco has issued free software to address these two flaws and also made workarounds available.
http://www.cisco.com/en/US/products/products_security_advisory09186a00807183b0.shtml
http://www.cisco.com/en/US/products/products_security_advisory09186a0080718330.shtml

5 Responses to “Cisco Warns of Flaw in Firewall Products”

  1. Chris Says:

    Interesting site! very informative… thanks!

  2. Richard Says:

    This is very interesting info. Thank you very much for sharing.

  3. Brianna Says:

    thanks for mentioning this

  4. Robert Says:

    Very nice site!

  5. Ange Says:

    Very nice site indeed!

Leave a Reply