VPN network error threatens wide-area data security

A flaw in the key Internet security protocol of most virtual private network products (VPNs) puts the enterprise system at risk of encountering various types of attacks, including DoS.

Picture 1 of VPN network error threatens wide-area data security

Researchers at the University of Oulu (Finland) said they have discovered a bug in network security technology and key management protocol (ISAKMP), used in IPsec virtual networks and firewall products. Many companies like Juniper Networks and Cisco.

" These errors can allow cybercriminals to attack denial of service, take advantage of vulnerabilities in formatted text strings, buffer overflows and reduce data transfer rates over the Internet. Certainly, the attacker also has the ability to handle code and control remote devices , "said the UK's National Infrastructure Security Center (NISCC).

Cisco said a security error could cause some of its devices to constantly reset, so it could create a denial of service attack. The company has released a free software upgrade and instructions here. The list of affected products includes Cisco IOS, Cisco PIX Firewall, Cisco Firewall Services Module, Cisco VPN 3000 Serie and MDS Series SanOS.

Juniper's affected products include all routers of the M, T, J, and E series, and most versions of Junos and JunoSe security software.

Openswan Project, IPsec software that appears in many Linux products, is also at risk. The support organization of this program has released Openswan 2.4.2 update as soon as it receives the notice.

IBM and Microsoft claim their systems are still safe.

TN ( CNet )