VPN network error threatens wide-area data security
A flaw in the key Internet security protocol of most virtual private network products (VPNs) puts the enterprise system at risk of encountering various types of attacks, including DoS.
" These errors can allow cybercriminals to attack denial of service, take advantage of vulnerabilities in formatted text strings, buffer overflows and reduce data transfer rates over the Internet. Certainly, the attacker also has the ability to handle code and control remote devices , "said the UK's National Infrastructure Security Center (NISCC).
Cisco said a security error could cause some of its devices to constantly reset, so it could create a denial of service attack. The company has released a free software upgrade and instructions here. The list of affected products includes Cisco IOS, Cisco PIX Firewall, Cisco Firewall Services Module, Cisco VPN 3000 Serie and MDS Series SanOS.
Juniper's affected products include all routers of the M, T, J, and E series, and most versions of Junos and JunoSe security software.
Openswan Project, IPsec software that appears in many Linux products, is also at risk. The support organization of this program has released Openswan 2.4.2 update as soon as it receives the notice.
IBM and Microsoft claim their systems are still safe.
TN ( CNet )
Researchers at the University of Oulu (Finland) said they have discovered a bug in network security technology and key management protocol (ISAKMP), used in IPsec virtual networks and firewall products. Many companies like Juniper Networks and Cisco.
" These errors can allow cybercriminals to attack denial of service, take advantage of vulnerabilities in formatted text strings, buffer overflows and reduce data transfer rates over the Internet. Certainly, the attacker also has the ability to handle code and control remote devices , "said the UK's National Infrastructure Security Center (NISCC).
Cisco said a security error could cause some of its devices to constantly reset, so it could create a denial of service attack. The company has released a free software upgrade and instructions here. The list of affected products includes Cisco IOS, Cisco PIX Firewall, Cisco Firewall Services Module, Cisco VPN 3000 Serie and MDS Series SanOS.
Juniper's affected products include all routers of the M, T, J, and E series, and most versions of Junos and JunoSe security software.
Openswan Project, IPsec software that appears in many Linux products, is also at risk. The support organization of this program has released Openswan 2.4.2 update as soon as it receives the notice.
IBM and Microsoft claim their systems are still safe.
TN ( CNet )
More Science Stories
- 10 worst moments of security industry
- Add a security error that threatens MS Excel
- Network security and data security in Vietnam: When the bell rings ...
- New vulnerability in Skype threatens users
- Drag-and-drop security error in IE
- D-Link product has a buffer overflow error
- QuickTime bug threatens XP, Vista
- Many network systems in Vietnam can be seriously affected by Webmin's error
- Where does the error 'Error 404' come from?
- See network security struggles like the front
- Upgrade wireless network security
- Error OpenOffice interconnects multiple operating systems