Update Protection against Cisco IOS HTTP Server Code Injection Vulnerability
| Check Point Reference: | CPAI-2006-028 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Cisco Security Advisory ID: 68322 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Cisco IOS HTTP Server version 11.0 through 12.4 (with the HTTP server enabled) | ||
| Vulnerability Description The Cisco IOS Web browser interface (which enables the device to perform as an HTTP server) allows configuration and monitoring of a router or access server using any Web browser. A vulnerability exists in the IOS HTTP server in the CDP, a proprietary Cisco protocol used for exchanging information between CISCO devices. Only Cisco products that run Cisco IOS Software versions 11.0 through 12.4 with the HTTP server enabled are affected. |
||
|
Vulnerability Details The vulnerability specifically exists due to insufficient filtering of user-supplied data which is displayed in the Cisco HTTP status pages. One of the status pages included in the IOS 11 HTML package displays information about current CDP protocol statistics. The Cisco Discovery Protocol (CDP) is a roprietary protocol that runs over Layer 2 (the data link layer) on the Content Services Switches (CSS) and other Cisco manufactured equipment, such as routers, switches, bridges, and access servers. |
Protection Overview
The Update enables the HTTP Worm Catcher to detect and block the vulnerability based on pre-defined worm signatures.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The update also includes the following protections:
- Enhancement to the Microsoft Windows Media Player Vulnerability (CPAI-2006-016)
- Trojan Spy Goldun.de Protection (CPAI-2006-025)
- ezDatabase Remote File Inclusion Protection (CPAI-2006-026)
- TFTPD32 Request Error Message Format String Protection (CPAI-2006-027) - InterSpect NGX only
- Cisco IOS CDP Status Page Code Injection Protection (CPAI-2006-028)
- SHOUTcast Filename Request Format String Protection (CPAI-2006-029)
- Oracle Report File Overwrite/Oracle Report Directory Traversal Protection (CPAI-2006-030)
- Google Talk via Gmail Web Interface Protection (CPSA-2006-02)
- IBM Tivoli Access Manager Directory Traversal Protection (CPAI-2006-031)
- Protection Against NFS Vulnerabilities (CPAI-2006-032)
- Protection against PmWiki multiple vulnerabilities.