OpticallyNetworked.com   Earthweb  
Images Events Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   subjects:
Search EarthWeb Network

internet.commerce
Be a Commerce Partner
Desktop Computers
Dental Insurance
IT Jobs
Merchant Accounts
Corporate Gifts
Mp3 Player Reviews
Memory
Cell Phone Plans
KVM over IP
Price Search
Health Insurance
Giveaways
Domain registration
IT Discount Club

Optically Networked : News: DoS Flaw in Cisco Router, Switches


Just click on the webcast of your choice to register:
Explore Business Intelligence Open Source Offerings
October 26, 2006--1:00pm EDT, 10:00am PDT
Join us and learn how the Business Objects XI platform embraces open source software (OSS) through its broad business intelligence (BI) offerings. Built on an open platform that can match disparate technologies environments deployed by application providers, Business Objects leads the BI industry by supporting OSS from Red Hat Linux and SuSE Linux operating systems, MySQL database and Eclipse IDE.
Register Now >
Transformation as an Enterprise Service
October 24, 2006--11:30am ET, 8:30am PT
Learn how to achieve interoperability between otherwise incompatible enterprise content management systems and transform legacy business functions to agile, SOA-enabled solutions. Register for this October 24th webcast, sponsored by Xenos.
Register Now >
Storage Strategies for Small Businesses
November 7, 2006--2 p.m. EST, 11 a.m. PST
When it comes to storage, small and medium businesses have a lot in common with large enterprises. Just like the Fortune 400, they need to ensure that data is backed up, retrievable and secure, and that data access complies with governmental regulations. Unfortunately, if you are a small business owner you also cope with some challenges the big guys don't have, budgets are small and your IT staff, if you even have one, may not have storage-specific expertise. Attend this webcast and learn storage strategies to meet your growing business demands.
Register Now >
Networking & Communications Glossary
directory service
honeynet
intranet
intrusion detection system
network appliance
NFS
port scanning
protocol
security
VPN
Search for more networking terms ...
 
FREE Tech Newsletters

DoS Flaw in Cisco Router, Switches
July 17, 2003
By Ryan Naraine

Cisco (Quote) has issued an alert for a denial-of-service (define) vulnerability in routers and switches running its Cisco IOS software and configured to process IPv4 packets.

Cisco, which dominate the market for switching and routing equipment used to link networks said a rare sequence of crafted IPv4 packets sent directly to the vulnerable device may cause the input interface to stop processing traffic once the input queue is full.

The flaw, described as "moderately critical" by research firm Secunia, could be compromised without authentication because processing of IPv4 packets is enabled by default. Devices running only IP version 6 (IPv6) are not affected, Cisco said.

On Ethernet interfaces, Cisco said the Address Resolution Protocol (ARP) times out after a default time of four hours causing a blockage of traffic flow. "The device must be rebooted to clear the input queue on the interface, and will not reload without user intervention. The attack may be repeated on all interfaces causing the router to be remotely inaccessible," the company warned.

According to the advisory, a device receiving these specifically crafted IPv4 packets will force the inbound interface to stop processing traffic. "The device may stop processing packets destined to the router, including routing protocol packets and ARP packets. No alarms will be triggered, nor will the router reload to correct itself," the company cautioned, noting that the vulnerability may be exercised repeatedly resulting in loss of availability until a workaround has been applied or the device has been upgraded to a fixed version of code.

Cisco released a patch and workaround for the flaw.

The Computer Emergency Response Team (CERT), in an accompanying advisory, urged network administrators to consider applying access control lists as an additional safeguard until the patch could be applied.

Cisco said it was not aware of any public announcements or malicious use of the vulnerabilities.


News Archives

Accelerate your applications 15x with Citrix NetScaler
Enterprise Networking Planet Webcast: Promoting an ID Management Strategy
Whitepaper: Learn Why Smart Money Trusts HP Integrity Servers w/ Itanium 2 Processors
Transform legacy business functions to agile, SOA-enabled solutions. Attend this webcast.
Video: Symantec Corporation's Senior Vice President, Discusses Powerful Security Solutions


JupiterWeb networks:

internet.comearthweb.comDevx.comGraphics.com

Search JupiterWeb:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterWeb

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Web Hosting | Newsletters | Tech Jobs | Shopping | E-mail Offers