{"id":147,"date":"2007-03-01T08:54:52","date_gmt":"2007-03-01T07:54:52","guid":{"rendered":"http:\/\/security-planet.de\/?p=145"},"modified":"2007-03-01T08:54:52","modified_gmt":"2007-03-01T07:54:52","slug":"month-of-the-cisco-bug","status":"publish","type":"post","link":"https:\/\/cyber-fi.net\/index.php\/2007\/03\/01\/month-of-the-cisco-bug\/","title":{"rendered":"Month of the Cisco Bugs"},"content":{"rendered":"<p>Hat eigentlich irgendwer im letzten Monat den &#8220;Month of the Cisco Bugs&#8221; ausgerufen? Das kam mir jedenfalls so vor:<\/p>\n<ul>\n<li><strong>31.1. <\/strong>SIP Packet Reloads IOS Devices Not Configured for SIP (habe ich erst Anfang Februar gelesen, daher mit in meiner kleinen Liste)<\/li>\n<li><strong>13.2. <\/strong>Multiple IOS IPS Vulnerabilities<\/li>\n<li><strong>14.2. <\/strong>Multiple Vulnerabilities in Cisco PIX and ASA Appliances<\/li>\n<li><strong>14.2. <\/strong>Multiple Vulnerabilities in Firewall Services Module<\/li>\n<li><strong>17.2.<\/strong>  Potential exploitation of default administrative credentials (in meinen Augen nicht wirklich ein Bug, hat aber zu der der interessanten neuen Option &#8220;one-time&#8221; beim username-Befehl gef\u00fchrt)<\/li>\n<li><strong>21.2.<\/strong> Cisco Unified IP Conference Station and IP Phone Vulnerabilities<\/li>\n<li><strong>21.2.<\/strong> Multiple Vulnerabilities in 802.1X Supplicant<\/li>\n<li><strong>28.2.<\/strong> Cisco Catalyst 6000, 6500 and Cisco 7600 Series MPLS Packet Vulnerability<\/li>\n<li><strong>28.2.<\/strong> Cisco Catalyst 6000, 6500 Series and Cisco 7600 Series NAM (Network Analysis Module) Vulnerability<\/li>\n<\/ul>\n<p>9 Verwundbarkeiten, mehr als beim &#8220;Month of the Apple Bugs&#8221;. Das Gute daran: Jetzt sind alle Bugs in Cisco-Systemen gefunden und gefixt; wir Cisco-Admins k\u00f6nnen wieder ruhig schlafen \ud83d\ude09<\/p>\n<p>Oder &#8230; hat eventuell sogar jemand das &#8220;Year of the Cisco Bugs&#8221; ausgerufen?<\/p>\n<ul>\n<li><strong>3.1.<\/strong> Multiple Vulnerabilities in Cisco Clean Access<\/li>\n<li><strong>6.1.<\/strong> Multiple Vulnerabilities in Cisco Secure Access Control Server<\/li>\n<li><strong>10.1.<\/strong> Cisco Unified Contact Center and IP Contact Center JTapi Gateway Vulnerability<\/li>\n<li><strong>10.1.<\/strong> DLSw Vulnerability<\/li>\n<li><strong>18.1.<\/strong> SSL\/TLS Certificate and SSH Public Key Validation Vulnerability<\/li>\n<li><strong>24.1.<\/strong>Crafted TCP Packet Can Cause Denial of Service<\/li>\n<li><strong>24.1.<\/strong> IPv6 Routing Header Vulnerability<\/li>\n<li><strong>24.1.<\/strong> Crafted IP Option Vulnerability<\/li>\n<\/ul>\n<p>Ok, dann wird es wohl noch weiter gehen und wir m\u00fcssen eventuell doch etwas l\u00e4nger aufbleiben, um unsere Systeme zu fixen. \ud83d\ude41 \ud83d\ude09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hat eigentlich irgendwer im letzten Monat den &#8220;Month of the Cisco Bugs&#8221; ausgerufen? Das kam mir jedenfalls so vor: 31.1. SIP Packet Reloads IOS Devices Not Configured for SIP (habe ich erst Anfang Februar gelesen, daher mit in meiner kleinen Liste) 13.2. Multiple IOS IPS Vulnerabilities 14.2. Multiple Vulnerabilities in Cisco PIX and ASA Appliances <\/p>\n<div class=\"read-more-text\"><a href=\"https:\/\/cyber-fi.net\/index.php\/2007\/03\/01\/month-of-the-cisco-bug\/\" class=\"read-more\">continue reading<\/a><\/div>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[5,7],"tags":[104],"class_list":["post-147","post","type-post","status-publish","format-standard","hentry","category-cisco","category-cisco-security","tag-bugs"],"_links":{"self":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/comments?post=147"}],"version-history":[{"count":0,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/posts\/147\/revisions"}],"wp:attachment":[{"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/media?parent=147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/categories?post=147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyber-fi.net\/index.php\/wp-json\/wp\/v2\/tags?post=147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}