Contact Us Today! (215) 853-2266

Bardissi Enterprises Blog

Bardissi Enterprises has been serving the Hatfield area since 2000, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

Cisco IOS + SSH = DoS

Severity: Medium

21 May, 2007

Summary:

  • These vulnerabilities affect: Cisco IOS 12.4 devices with SSH enabled
  • How an attacker exploits them: By sending specially crafted SSH packets
  • Impact: An attacker could repeatedly reboot your Cisco IOS device, keeping it offline for as long as he could sustain his attack
  • What to do: Download and install the appropriate Cisco update as soon as possible

Exposure:

Cisco’s IOS software is the operating system that runs on most Cisco routers and switches. The IOS operating system provides network services for managing Cisco devices, and processes the network traffic passing through the device. IOS also ships with an optional SSH server that allows you to securely manage your IOS device via an encrypted Command Line Interface (CLI).

Severity: Medium

21 May, 2007

Summary:

  • These vulnerabilities affect: Cisco IOS 12.4 devices with SSH enabled
  • How an attacker exploits them: By sending specially crafted SSH packets
  • Impact: An attacker could repeatedly reboot your Cisco IOS device, keeping it offline for as long as he could sustain his attack
  • What to do: Download and install the appropriate Cisco update as soon as possible

Exposure:

Cisco’s IOS software is the operating system that runs on most Cisco routers and switches. The IOS operating system provides network services for managing Cisco devices, and processes the network traffic passing through the device. IOS also ships with an optional SSH server that allows you to securely manage your IOS device via an encrypted Command Line Interface (CLI).

Today, Cisco released an advisory describing multiple vulnerabilities affecting the SSH server that runs on Cisco IOS devices. Cisco doesn’t describe these flaws in technical detail, but they admit that a remote attacker could exploit them to reboot your IOS device. By repeatedly exploiting these DoS vulnerabilities, an attacker could keep IOS devices, like your gateway router, offline for as long as he could sustain his attack.

One mitigating factor lowers the severity of these vulnerabilities: Cisco IOS does not enable the SSH server by default. Your Cisco IOS devices are only vulnerable to these flaws if you have manually enabled the SSH server. We assume that most Cisco administrators prefer to manage their IOS devices securely, and have enabled SSH for that very reason. Even if you haven’t enabled the SSH server, however, we still suggest you apply Cisco’s update to make sure you (or another staff member) cannot accidentally enable the vulnerable SSH server in the future.

Solution Path:

Cisco has released patches to fix these vulnerabilities. If you use any Cisco device running IOS 12.4 software, you should immediately consult the “Software Versions and Fixes†and “Obtaining Fixed Software†section of Cisco’s advisory to learn which fixes apply to your devices, and how to obtain them.

For All WatchGuard Users:

Since this vulnerability can affect your router, which is typically in front of your WatchGuard firewall, Cisco’s patches are the best solution.

Status:

Cisco has issued patches which fix the problem.

References:

Cisco’s IOS SSH Server Advisory

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 26 June 2025
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Mobile? Grab this Article!

QR-Code dieser Seite

Blog Archive

Recent Comments

Tip of the Week: Which Headphones are Right for Your Needs?
23 April 2018
I will recommend Plantronics Backbeat Pro 2 SE Noise cancelling Headset with it's Great features.
Gamification: Make Business Fun for Everyone
27 January 2017
The world is based on the games. There are many types of games as per the aussie essay writing servi...
Let's Talk Tablets
12 January 2017
The concept of tablet is far better than that of PC because you can bring them with you everywhere a...
Tip of the Week: Tweak Your Workday in These 4 Ways and See Major Results
12 January 2017
The only thing will I will say regarding this blog is that it is very helpful at least for me. As I ...
WatchGuard Releases Version 10.2.7 for WSM, Edge, Fireware, and Fireware Pro
23 December 2016
I really needed to know about the fireware but i was confused that where can i find information abou...