Cisco announced multiple security advisories
Last week, Cisco announced more security advisories regarding multiple possible vulnerabilities for range of it’s product. I will post here just a short summary about this advisories and provide you with the links to the full descriptions of the possible problems:
October 14, 2009 – Cisco Unified Presence Denial of Service Vulnerabilities
Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that may cause an interruption to presence services. These vulnerabilities were discovered internally by Cisco, and there are no workarounds.
Cisco has released free software updates that address these vulnerabilities.
October 15, 2009 – Multiple Vulnerabilities in Cisco Wireless LAN Controllers
Multiple vulnerabilities exist in the Cisco Wireless LAN Controller (WLC) platforms. This security advisory outlines the details of the following vulnerabilities:
Malformed HTTP or HTTPS authentication response denial of service vulnerability
SSH connections denial of service vulnerability
Crafted HTTP or HTTPS request denial of service vulnerability
Crafted HTTP or HTTPS request unauthorized configuration modification vulnerability
Cisco has released free software updates that address these vulnerabilities.
October 19, 2009 – Cisco IOS Software Tunnels Vulnerability
Cisco devices running affected versions of Cisco IOS Software are vulnerable to a denial of service (DoS) attack if configured for IP tunnels and Cisco Express Forwarding.
Cisco has released free software updates that address this vulnerability.
October 15, 2009 – Cisco IOS Software Authentication Proxy Vulnerability
Cisco IOS® Software configured with Authentication Proxy for HTTP(S), Web Authentication or the consent feature, contains a vulnerability that may allow an unauthenticated session to bypass the authentication proxy server or bypass the consent webpage.
Cisco has released free software updates that address this vulnerability.
There are no workarounds that mitigate this vulnerability.
October 19, 2009 – Cisco IOS Software Internet Key Exchange Resource Exhaustion Vulnerability
Cisco IOS® devices that are configured for Internet Key Exchange (IKE) protocol and certificate based authentication are vulnerable to a resource exhaustion attack. Successful exploitation of this vulnerability may result in the allocation of all available Phase 1 security associations (SA) and prevent the establishment of new IPsec sessions.
Cisco has released free software updates that address this vulnerability.
Which WAN Optimization vendor will consolidate and expand its market position on 2011
447 votes - Thank you all!I add the results in a blog posts so we can see over years on which [more]
CCIE home rack - Ubuntu persistent net rules
In one of my last posts, I was writing about my CCIE home rack which has one server that runs Ubuntu + [more]
Black Friday 2011 - 50% Off on INE bundles
If anybody is interested in buying INE products, do it now. I've got the following marketing e-mail. The [more]
Free streaming course CCNA 640-802 from INE
I'm sure that a lot of people out there got this info already, but for those who are not part of INE [more]
Home lab for CCIE exam training
Before I started with my preparation I was in front of a dilemma. I knew that I will need a rack to [more]
Professionals Blogs
- etherealmind.com
Close preview
Loading... - mellowd.co.uk
Close preview
Loading... - Cisco Network Engineer Blog
Close preview
Loading... - blindhog.net
Close preview
Loading... - CCIECisco
Close preview
Loading... - danielhertzberg.wordpress.com
Close preview
Loading... - globalconfig.net
Close preview
Loading... - blog.ioshints.info
Close preview
Loading... - packetlife.net
Close preview
Loading... - cisco-tips.com
Close preview
Loading... - gns3-labs.com
Close preview
Loading... - brainbump.net
Close preview
Loading... - bradhedlund.com
Close preview
Loading... - packet-forwarding.net
Close preview
Loading... - amyengineer.wordpress.com
Close preview
Loading... - noshut.blogspot.com
Close preview
Loading... - routing-bits.com
Close preview
Loading...
- etherealmind.com




