FEATURED VIDEO
Sponsored By:
SLIDE SHOWS
As if they needed more stress, organizations are facing evolving and increasingly stringent compliance regulations from the Payment Card Industry, as well as Sarbanes-Oxley, HIPAA and others. Here are a few security compliance products that can make the audit process less excruciating.
Here are 10 of the distributor's hottest new offerings winning over solution providers.
New smartphones from Sony, Motorola and the first-ever Twitter-only mobile device -- the TwitterPeek -- headline a busy week for handset makers as the holiday shopping season heats up.
INSIDE CHANNELWEB

Cisco Issues Five Security Alerts


By Stefanie Hoffman, ChannelWeb

3:51 PM EDT Thu. Jun. 05, 2008
Cisco issued a security advisory today for multiple vulnerabilities in its Cisco ASA 5500 Series Adaptive Security Appliance and the Cisco PIX Security Appliances, all but one of which could lead to a denial of service attack.

The Cisco ASA 5500 is a modular platform providing security and VPN services, while the Cisco PIX appliance is a security device protecting Internet connections geared for remote and branch offices.

Altogether, four denial of service vulnerabilities can be found in the Crafted TCP ACK Packet, the Crafted TLS Packet, the Vulnerability Scan and the Instant Messenger inspection, which includes a glitch that could lead to a denial of service attack in the Cisco ASA and Cisco PIX if the inspection engine was enabled.

The fifth error, a Control-Plane Access Control List vulnerability, could potentially enable an attacker to bypass security restrictions on the control-plane access control lists without authorization. Exploiting an error in the Control-Plane Access Control List, which is designed to protect traffic destined to the security appliance, could cause the control plane ACL not to work after it is configured to the device.

Following release of the Cisco advisory, the U.S. Computer Emergency Readiness Team also released an alert on its Web site today, warning users of the flaws.

The error in the Crafted TCP ACK is the only bug that comes with a workaround. The flaw could cause a denial of service condition on ASA and PIX devices running versions 7.1x and 7.2x with WebVPN, SSL VPN or ASDM.

Experts recommend that users update their systems with the appropriate fixes as soon as possible, which can be downloaded for free to users. So far, experts say that there doesn't appear to be a known public attack exploiting these vulnerabilities.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
Avnet 0% Lease Promotion
The Avnet Capital Solutions “0% Lease Promotion” has been extended to December 31, 2009! This offering significantly reduces ...
Double Your Money!
Cash Rewards - DOUBLED!
RELATED BLOG >>
Photo
LogLogic takes complex log data and turns it into something manageable.
ADVERTISEMENT




CHANNEL SERVICES >>