S-319: Cisco Intrusion Prevention System Vulnerability


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) S-319: Cisco Intrusion Prevention System Vulnerability
# 1  
Old 06-19-2008
S-319: Cisco Intrusion Prevention System Vulnerability

Cisco Intrusion Prevention System (IPS) platforms that have gigabit network interfaces installed and are deployed in inline mode contain a denial of service vulenrability in the handling of jumbo Ethernet frames. This vulnerability may lead to a kernel panic that requires a power cycle to recover platform operaiton. The risk is MEDIUM. Successful exploitation of the vulnerability may result in a network denial of service condition. A power cycle is required to recover operations. An attacker may be able to evade access controls and detection of malicious activity int he case of Cisco IPS 4260-4270 platforms that have hardware bypass configured to pass traffic in the event of a kernel panic.


More...
Login or Register to Ask a Question

Previous Thread | Next Thread

1 More Discussions You Might Find Interesting

1. Cybersecurity

Intrusion Detection - System Call Introspection

can u give me a code for host based intrusion detection using system call introspection... (5 Replies)
Discussion started by: aravind007
5 Replies
Login or Register to Ask a Question
Info::Layer2::Airespace(3pm)				User Contributed Perl Documentation			      Info::Layer2::Airespace(3pm)

NAME
SNMP::Info::Layer2::Airespace - SNMP Interface to Cisco (Airespace) Wireless Controllers AUTHOR
Eric Miller SYNOPSIS
#Let SNMP::Info determine the correct subclass for you. my $airespace = new SNMP::Info( AutoSpecify => 1, Debug => 1, DestHost => 'myswitch', Community => 'public', Version => 2 ) or die "Can't connect to DestHost. "; my $class = $airespace->class(); print " Using device sub class : $class "; DESCRIPTION
Provides abstraction to the configuration information obtainable from Cisco (Airespace) Wireless Controllers through SNMP. For speed or debugging purposes you can call the subclass directly, but not after determining a more specific class using the method above. my $airespace = new SNMP::Info::Layer2::Airespace(...); Inherited Classes SNMP::Info::Airespace SNMP::Info::CDP SNMP::Info::Bridge Required MIBs Inherited Classes' MIBs See "Required MIBs" in SNMP::Info::Airespace for its own MIB requirements. See "Required MIBs" in SNMP::Info::CDP for its own MIB requirements. See "Required MIBs" in SNMP::Info::Bridge for its own MIB requirements. GLOBALS
These are methods that return scalar value from SNMP $airespace->vendor() Returns 'cisco' $airespace->os() Returns 'cisco' $airespace->model() ("agentInventoryMachineModel") Global Methods imported from SNMP::Info::Airespace See documentation in "GLOBALS" in SNMP::Info::Airespace for details. Global Methods imported from SNMP::Info::CDP See documentation in "GLOBALS" in SNMP::Info::CDP for details. Globals imported from SNMP::Info::Bridge See documentation in "GLOBALS" in SNMP::Info::Bridge for details. TABLE METHODS
These are methods that return tables of information in the form of a reference to a hash. cd11_mac() Overrides Table Methods imported from SNMP::Info::Airespace See documentation in "TABLE METHODS" in SNMP::Info::Airespace for details. Table Methods imported from SNMP::Info::CDP See documentation in "TABLE METHODS" in SNMP::Info::CDP for details. Table Methods imported from SNMP::Info::Bridge See documentation in "TABLE METHODS" in SNMP::Info::Bridge for details. MUNGES
munge_64bits() munge_cd11_rateset() munge_cd11_txrate() perl v5.12.4 2011-09-28 Info::Layer2::Airespace(3pm)