Home > Security News > Cisco patches latest IOS security hole
Security News:
EMAIL THIS LICENSING & REPRINTS

Cisco patches latest IOS security hole

By Bill Brenner, Senior News Writer
26 Jan 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Cisco Systems Inc. has issued a patch for its Internetwork Operating System (IOS), closing a security hole attackers could use to bypass command authorization checks and gain escalated user privileges.

The vulnerability exists within the IOS Authentication, Authorization, and Accounting (AAA) command authorization feature, "where command authorization checks are not performed on commands executed from the Tool Command Language (Tcl) exec shell," Cisco said in its advisory. "This may allow authenticated users to bypass command authorization checks in some configurations, resulting in unauthorized privilege escalation."

More on IOS

Cisco warns of IOS, OpenSSL flaws

Cisco patches IOS flaw

Cisco IOS flaw prompts Symantec to raise threat level

Researcher causes furor by releasing flaw in Cisco IOS

The vulnerability affects IOS version 12.0T or later. Cisco said devices that don't run the AAA command authorization feature or don't support Tcl functionality are not affected by the flaw.

The San Jose, Calif.-based networking giant also warned that an authenticated user is automatically placed into the Tcl shell mode if a previous user goes into Tcl shell mode and terminates the session before leaving the Tcl shell mode. This could exacerbate the vulnerability, the company said.

The patch is the latest in a series of steps Cisco has taken to address security holes in the past week.

It patched two security holes in CallManager -- the software-based call-processing component of its IP telephony products -- and offered workarounds for a glitch in the (IOS) HTTP Server.

Tags: TCP/IPNetwork Device ManagementEndpoint SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google




More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts