|
From: Cisco Systems Product Security Incident Response Team <psirt@cisco.com>
Date: Mon Dec 15 2003 - 10:30:51 CST
-----BEGIN PGP SIGNED MESSAGE-----
Cisco Security Advisory: Cisco PIX Vulnerabilities
Revision 1.0
For Public Release 2003 December 15 at 1600 UTC (GMT)
----------------------------------------------------------------------
Contents
Summary
----------------------------------------------------------------------
Summary
This advisory documents two vulnerabilities for the Cisco PIX firewall.
There are workarounds available to mitigate the effects of CSCeb20276
This advisory will be posted at
Affected Products
All Cisco PIX firewall devices running the affected Cisco PIX firewall
* CSCeb20276 (SNMPv3)
6.3.1, 6.2.2 and earlier, 6.1.4 and earlier. 5.x.x and earlier.
* CSCec20244/CSCea28896 (VPNC)
6.2.3 and earlier.
6.1.x and 5.x.x are not affected; they do not implement the VPNC
The Firewall Service Module (FWSM) is also vulnerable to the SNMPv3 issue
To determine your software revision, type show version at the command line
Details
* CSCeb20276 (SNMPv3)
The Cisco PIX firewall crashes and reloads while processing a received
* CSCec20244/CSCea28896 (VPNC)
Under certain conditions an established VPNC IPSec tunnel connection
Only a Cisco PIX firewall configured as a VPN Client is vulnerable to
A VPNC, also referred to as Easy VPN or ezVPN, connection is created
CSCea28896 resolved this issue for the 6.3.x software releases and
The Internetworking Terms and Cisco Systems Acronyms online guides can be
These vulnerabilities are documented in the Cisco Bug Toolkit as Bug ID
Impact
* CSCeb20276 (SNMPv3)
This vulnerability can be exploited to initiate a Denial of Service
* CSCec20244/CSCea28896 (VPNC)
This vulnerability can be exploited to initiate a Denial of Service
Software Versions and Fixes
* CSCeb20276 (SNMPv3)
6.3.2 and later, 6.2.3 and later, 6.1.5 and later.
* CSCec20244/CSCea28896 (VPNC)
6.3.1 and later, 6.2(3.100) and later.
The procedure to upgrade to the fixed software version is detailed at
Obtaining Fixed Software
Cisco is offering free software upgrades to address these vulnerabilities
Customers may only install and expect support for the feature sets they
Customers with contracts should obtain upgraded software through their
Customers whose Cisco products are provided or maintained through prior or
Customers who purchase direct from Cisco but who do not hold a Cisco
Cisco TAC contacts are as follows.
* +1 800 553 2447 (toll free from within North America)
* +1 408 526 7209 (toll call from anywhere in the world)
* e-mail: tac@cisco.com
See http://www.cisco.com/warp/public/687/Directory/DirTAC.shtml for
Please have your product serial number available and give the URL of this
Please do not contact either "psirt@cisco.com" or
Workarounds
* CSCeb20276 (SNMPv3)
There are two workarounds available.
* Restrict access to only allow trusted hosts on specific
snmp-server host <if_name> <ip_addr> poll
* Disable the SNMP server on the Cisco PIX firewall as follows:
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
Note: The Cisco PIX firewall does not allow one to remove the
More details at
* CSCec20244/CSCea28896 (VPNC)
No workaround. Please upgrade.
The Cisco PSIRT recommends that affected users upgrade to a fixed software
Exploitation and Public Announcements
The Cisco PSIRT is not aware of any public announcements or malicious use
CSCeb20276 (SNMPv3) was reported to the PSIRT by Rasto Rickardt.
Status of This Notice: Final
This is a final advisory. Although Cisco cannot guarantee the accuracy of
A stand-alone copy or paraphrase of the text of this security advisory
Distribution
This advisory will be posted on Cisco's worldwide website at
In addition to worldwide web posting, a text version of this notice is
* cust-security-announce@cisco.com
* first-teams@first.org (includes CERT/CC)
* bugtraq@securityfocus.com
* vulnwatch@vulnwatch.org
* cisco@spot.colorado.edu
* cisco-nsp@puck.nether.net
* full-disclosure@lists.netsys.com
* comp.dcom.sys.cisco@newsgate.cisco.com
* Various internal Cisco mailing lists
Future updates of this advisory, if any, will be placed on Cisco's
Revision History
+------------------------------------------+
Cisco Security Procedures
Complete information on reporting security vulnerabilities in Cisco
This advisory is copyright 2003 by Cisco Systems, Inc. This advisory may
----------------------------------------------------------------------
iD8DBQE/3dv7ezGozzK2tZARApv1AKCC76rvb2QxkYiOOI4+zFmSXr49EwCg9Ps8
_______________________________________________
This archive was generated by hypermail 2.1.8 : Mon Dec 15 2003 - 12:01:01 CST |
Custom Search
|