A vulnerability exists in the Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers that may cause the Cisco FWSM to reload after processing a malformed Skinny Client Control Protocol (SCCP) message. The vulnerability exists when SCCP inspection is enabled.
Cisco has released free software updates that address this vulnerability.
All non-fixed 4.x versions of Cisco FWSM Software are affected by this vulnerability if SCCP inspection is enabled. SCCP inspection is enabled by default.
To check if SCCP inspection is enabled, issue the show service-policy | include skinny command and confirm that the command returns output. Example output follows:
fwsm#show service-policy | include skinny
Inspect: skinny , packet 0, drop 0, reset-drop 0
If SCCP inspection is not required, this vulnerability can be mitigated by disabling it. Administrators can disable SCCP inspection by issuing the no inspect skinny command in class configuration sub-mode within the policy map configuration. If SCCP inspection is required, there are no workarounds.
Cisco has released free software updates that address this vulnerability. Prior to deploying software, customers should consult their maintenance provider or check the software for feature set compatibility and known issues specific to their environment.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20100217-fwsm.shtml
Which WAN Optimization vendor will consolidate and expand its market position on 2011
447 votes - Thank you all!I add the results in a blog posts so we can see over years on which [more]
CCIE home rack - Ubuntu persistent net rules
In one of my last posts, I was writing about my CCIE home rack which has one server that runs Ubuntu + [more]
Black Friday 2011 - 50% Off on INE bundles
If anybody is interested in buying INE products, do it now. I've got the following marketing e-mail. The [more]
Free streaming course CCNA 640-802 from INE
I'm sure that a lot of people out there got this info already, but for those who are not part of INE [more]
Home lab for CCIE exam training
Before I started with my preparation I was in front of a dilemma. I knew that I will need a rack to [more]
Professionals Blogs
- blindhog.net
Close preview
Loading... - danielhertzberg.wordpress.com
Close preview
Loading... - blog.ioshints.info
Close preview
Loading... - cisco-tips.com
Close preview
Loading... - etherealmind.com
Close preview
Loading... - mellowd.co.uk
Close preview
Loading... - brainbump.net
Close preview
Loading... - packet-forwarding.net
Close preview
Loading... - noshut.blogspot.com
Close preview
Loading... - gns3-labs.com
Close preview
Loading... - bradhedlund.com
Close preview
Loading... - Cisco Network Engineer Blog
Close preview
Loading... - amyengineer.wordpress.com
Close preview
Loading... - routing-bits.com
Close preview
Loading... - CCIECisco
Close preview
Loading... - globalconfig.net
Close preview
Loading... - packetlife.net
Close preview
Loading...
- blindhog.net





Pingback: Cisco FWSM SCCP Inspection DoS Vulnerability | FirstDigest