Slashdot Mirror


Cisco Fixes Three-Year-Old Telnet Flaw In Security Appliances

Trailrunner7 writes "There is a severe remote code execution vulnerability in a number of Cisco's security appliances, a bug that was first disclosed nearly three years ago. The vulnerability is in Telnet and there has been a Metasploit module available to exploit it for years. The FreeBSD Project first disclosed the vulnerability in telnet in December 2011 and it was widely publicized at the time. Recently, Glafkos Charalambous, a security researcher, discovered that the bug was still present in several of Cisco's security boxes, including the Web Security Appliance, Email Security Appliance and Content Security Management Appliance. The vulnerability is in the AsyncOS software in those appliances and affects all versions of the products." At long last, though, as the article points out, "Cisco has released a patched version of the AsyncOS software to address the vulnerability and also has recommended some workarounds for customers."

4 of 60 comments (clear)

  1. Security + Telnet by MightyYar · · Score: 5, Insightful

    Security + Telnet = My Brain Hurts

    --
    W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    1. Re:Security + Telnet by 3.5+stripes · · Score: 4, Insightful

      Yeah, any sort of security guidelines should have at the top, in the largest boldest letters possible, DO NOT USE TELNET.

      --


      He tried to kill me with a forklift!
    2. Re:Security + Telnet by CaptnZilog · · Score: 4, Informative

      I use telnet plenty great for connecting to a tcp port and debugging. It's a horrid thing to run as a service and allow people to login etc.

      Yeah, the client comes in handy at times to connect to port 80 and 'handcraft' a http request to see a response, etc... but running a telnet server/service on the machine? Especially on a "security" device?!?!? C'mon... that's just ludicrous in all kinds of ways.

  2. Thank Goodness! by linuxrunner · · Score: 5, Funny

    I've been waiting for this fix so I can finally drop SSH

    --
    www.slightlycrewed.com - Because aren't we all?