Skip to main content /TECH with IDG.net
CNN.com /TECH
CNN TV
EDITIONS

Flaw revealed in some Cisco software

image
Network World Fusion

(IDG) -- Cisco Systems has warned customers of a flaw in its Internetwork Operating System (IOS) software that could compromise the integrity of Transmission Control Protocol (TCP) traffic sent to and from its routers and switches.

The vulnerability exists in all released versions of IOS, and hence affects all Cisco routers and switches running the software, the company said in a security advisory issued last week. Cisco's data networking equipment is the most widely used to carry traffic on the Internet.

MESSAGE BOARD
 
IDG.net INFOCENTER
IDG.net
Related IDG.net Stories
Visit an IDG site


IDG.net search



The security flaw can allow the successful prediction of TCP Initial Sequence Numbers, Cisco said. Such numbers are supposed to be randomly generated by a sending machine and its receiving host as part of setting up a new IOS connection. Once the initial transmission is established, a sequence number is created based on the amount of data transmitted.

However, if the initial number is not random, then it is possible "with varying degrees of success, to forge one half of a TCP connection with another host in order to gain access to that host, or hijack an existing connection between two hosts in order to compromise the contents of the TCP connection," Cisco said in the advisory.

No Cisco customers had reported any attacks because of the vulnerability as of Thursday afternoon, a Cisco spokeswoman said. However, one analyst noted that with so much of the Internet running on Cisco equipment, any problem with its networking gear has the potential to become significant.

"Anything that poses a flaw to Cisco is something to be alarmed about, since they control about 80 percent of the router market," said Irwin Lazar, senior consultant with analyst firm The Burton Group Corp.

"The biggest issue out there is that people don't want to just slap an IOS upgrade in their routers without testing it first, in case another problem popped up when they corrected this one," he added.

The flaw affects the security only of TCP connections that originate or terminate on the Cisco device itself, not of any traffic that passes through the device in transit. Cisco said it is offering free software upgrades for affected customers.




RELATED STORIES:
Cisco switch users irked over delays
January 18, 2001
Cisco raises its VoIP
April 3, 2000
Cisco recalls switch modules
January 6, 2000
Cisco, 10 others in wireless 'Net push
October 28, 1999
Is Cisco choking broadband pipes?
July 30, 1999
Cisco to sign up for NDS
November 19, 1998

RELATED IDG.net STORIES:
Cisco Web switches found to have security cracks
(Network World Fusion)
New Cisco router could pave way for new IP services
(Network World Fusion)
Cisco set to roll out high-speed optical router
(Network World Fusion)
A lesson in Cisco-speak
(The Industry Standard)
Software vs. hardware routers compared
(Network World Fusion)
Core routing: Juniper keeps gaining on Cisco
(Network World Fusion)
Cisco CEO optimistic about future
(InfoWorld.com)
Update: Cisco finally ratchets up to 10 gigabits
(Network World Fusion)

RELATED SITES:
Cisco Systems, Inc.



Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.


 Search   





MARKETS
4:30pm ET, 4/16
144.70
8257.60
3.71
1394.72
10.90
879.91
 













Back to the top