Home > Networking News > Cisco stamps patches on timestamp flaws
Networking News:
EMAIL THIS

Cisco stamps patches on timestamp flaws

By Amy Storer, News Writer
19 May 2005 | SearchNetworking.com

News on networking, mobility and voice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Several reported vulnerabilities in Cisco Systems Inc.'s products can be exploited to cause denial-of-service conditions on active Transmission Control Protocol (TCP) sessions.

The product flaws, confirmed in an update released by Cisco and classified as low risk in a Secunia advisory posted this morning, include:

  • Cisco Aironet 1200 Series Access Point
  • Cisco Aironet 350 Series Access Point
  • Cisco Content Services Switch 11000 Series (WebNS)
  • Cisco MGX 8200 Series Edge Concentrators
  • Cisco MGX 8800 Series Multiservice Switches
  • Cisco MGX 8900 Series Multiservice Switches
  • Cisco SN5400 Series Storage Routers

    For more information

    Check out our white paper on managing Cisco network security.

    Learn more about troubleshooting VPNs.

    The vulnerability is caused due to a TCP timestamp option error. The flaws allow a remote user to send a packet with specially crafted TCP timestamp options, ultimately causing a target TCP connection to stall until the TCP connection is reset.

    The advisory said knowledge of IP address information of the source and destination of the TCP network connection is required for successful exploitation.

    Only systems running VxWorks, a real-time operating system for embedded software and process control applications, are affected.

    Systems running VxWorks can be upgraded to Cisco IOS to address this issue; access points running Cisco IOS are not affected.

    The Cisco advisory recommends that users apply vendor-provided patches.

    Tags: Network Security Monitoring and AnalysisTroubleshooting Wireless NetworksWLAN SecurityWireless Network SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Network Security Monitoring and Analysis
    Application-specific network intrusion detection systems emerge
    Anomaly-based intrusion protection configuration and installation
    How can I calculate perimeter firewall throughput?
    How do I find the application on my network that's dropping packets?
    Integrating NAC with network security tools
    Where can I find a sample security audit report? How can I run my own?
    The firewall remains the network traffic cop, but its role is changing
    Troubleshooting VLANs: How to monitor 802.1q tagged traffic
    Poor data-loss prevention practices almost cost Intel a billion
    How can I block my competitor's IP address range from my website?

    Troubleshooting Wireless Networks
    University tackles large-scale 802.11n wireless network management
    Why is my network adapter not working after a Vista Business upgrade?
    Meru reinvents wireless LAN troubleshooting and management
    APs drop connection in WLAN configured as a wireless mesh network
    How to plan for 802.11n wireless LAN upgrades
    Vendors strive to automate wireless LAN troubleshooting and management
    Fluke gets WLAN design, management, security cred with AirMagnet
    Wi-Fi RTLS for WLAN management, location-based security, asset tracking
    How radio frequency (RF) of microwaves alter wireless signal strength
    Distributed antenna systems and WLAN: A network management burden
    Troubleshooting Wireless Networks Research

    WLAN Security
    Where can I find a wire driver that unblocks recognized passwords?
    Will using a VPN protect me against fake wireless hotspots?
    Fluke gets WLAN design, management, security cred with AirMagnet
    Is WPA2 secure enough for a commercial business wireless network?
    Health center cut cost securing wireless network edge with Aerohive
    Wi-Fi RTLS for WLAN management, location-based security, asset tracking
    Wireless LAN performance management and security standards beefed up
    How can I hide my WLAN's SSID in an Aruba AP-61?
    Wireless LAN security: SonicWall joins crowded WLAN market
    Stolen laptop recovery using remote access and wireless network SSIDs

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    deep packet inspection (DPI)  (SearchNetworking.com)
    FCAPS  (SearchNetworking.com)
    Nessus  (SearchNetworking.com)
    netstat  (SearchNetworking.com)
    port mirroring  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • Comprehensive network management resources, expert solutions, and professional research informing your technology decisions
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts