Skip to main content /TECH with /TECH

Software flaw opens Cisco devices to hackers

Network World Fusion

By Joris Evers

(IDG) -- A flaw in Cisco Internetwork Operating System could allow hackers to gain full control over virtually all Cisco routers and switches using the software, Cisco said in a security advisory issued Thursday. INFOCENTER
Related Stories
Visit an IDG site search

The Computer Emergency Response Team at Carnegie Mellon University in Pittsburgh also warned of the vulnerability later Thursday.

A vulnerability exists in the HTTP server component of the IOS software. By requesting a particular URL from the server, a malicious user can bypass the authentication controls and execute commands on the device at the highest privilege level, Level 15, Cisco said.

Only devices with the HTTP server software enabled and with user names and passwords stored on the device -- the local authentication database -- are vulnerable, the company said. The issue affects all releases of Cisco IOS software starting with Release 11.3.

Once a hacker has gained access he could redirect data traffic, allowing him to intercept or modify the data. Additionally he could change or delete the device configuration, effectively disabling the router or switch until an engineer reprograms it, said Cisco Security and Network Management Systems Engineer Tames van der Does.

The HTTP server in IOS is used for remote management of the router or switch. However, a configuration with the HTTP server enabled and the local database for authentication used is a rarity, according to Van der Does.

"Most engineers use Telnet to access their network hardware and have a central Terminal Access Controller Access Control System or Radius server to authenticate users for all their networking hardware," he said, adding that the HTTP server is switched off by default on Cisco hardware.

Routers and switches direct network traffic and are used to interconnect computer networks. Cisco's hardware is used around the world by small and large businesses as well as home users.

Cisco has made software fixes available to plug the hole.

• Cisco advisory and security patch
• Cisco Systems

Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.


Back to the top