A vulnerability with Cisco routers when access lists are utilized. This vulnerability is present in Cisco software releases 8.2, 8.3, 9.0 and 9.1. From my personal point of view i personally strongly recommend that sites using Cisco routers for firewalls take immediate action to eliminate this vulnerability from their networks.

This vulnerability is fixed in Cisco software releases 8.3 (update 5.10), 9.0 (update 2.5), 9.1 (update 1.1) and in all later releases. Administrators who are using software release 8.2 and do not want to upgrade to a later release should contact Cisco’s Technical Assistance Center (TAC) at 800-553-2447 (Internet: tac@cisco.com) for more information.

The following interim releases are available
—————————————————————

Release (Update) Filename Size Checksum
8.3 (5.10) /beta83_dir/gs3-bfx.83-5.10 1234696 02465 1206
9.0 (2.5) /beta90_dir/gs3-bfx.90-2.5 1705364 47092 1666
9.1 (1.1) /beta91_dir/gs3-k.91-1.1 2005548 59407 1959

These releases are also available on Cisco’s Customer Information On-Line (CIO) service for those having a maintenance contract.Other customers may obtain these releases through Cisco’s Technical Assistance Center or by contacting their local Cisco distributor.

- —————————————————————————–

I. Description

A vulnerability in Cisco access lists allows some packets to be erroneously routed which one would expect to be filtered by the access list and vice-versa. This vulnerability can allow unauthorized traffic to pass through the gateway and can block authorized traffic.

II. Problem

If a Cisco router is configured to use extended IP access lists for traffic filtering on an MCI, SCI, cBus or cBusII interface, and the IP route cache is enabled, and the “established” keyword is used in the access list, then the access list can be improperly evaluated. This can permit packets which should be filtered and filter packets which should be permitted.

III. Workaround

This vulnerability can be avoided by either rewriting the extended access list to not use the “established” keyword, or by configuring the interface to not use the IP route cache. To disable the IP route cache, use the configuration command “no ip route-cache”.

Example for a serial interface:
router>enable

Password:
router#configure terminal

Enter configuration commands, one per line.
Edit with DELETE, CTRL/W, and CTRL/U; end with CTRL/Z
interface serial 0
no ip route-cache
^Z
router#write memory

IV. Solution

Obtain and install the appropriate interim release listed above. Sites which are not experienced at this installation process
should contact the TAC center at 800-553-2447 for assistance.

  • Share/Bookmark

Optimizing Wireless Communication Systems presents the underlying technological breakthroughs that allowed the current state of wireless technology development to evolve. The focus is on the two lower layers of the ISO/OSI layered model, specifically the physical and data link layers including the link and media access control sublayers. These two layers are of particular importance [...]

Telecommunications in Europe (Communication and Society) Free eBook download.
Publisher: Oxford University Press, USA 1992-08-20 | 536 Pages | ISBN: 0195070526 | PDF | 31 MB
Telecommunications represents one of the largest high technology equipment and service industries in the world. Today there is growing support within the telecommunications industry for competition domestically and in world trade which is [...]

The capital city of India, Delhi, has become the first city in the country to have a telecom penetration rate of more than 100 percent. New data from the government suggest that Delhi has a mobile teledensity of 109.9 percent. Delhi had around 19 million mobile users at the end of October and has become [...]

Bharti Airtel CEO-designate Sanjay Kapoor i s taking over the reins of the company at a time when the telco is struggling

to meet the high standards set by it. Its revenue growth and market share have slipped and the pace of customer additions has eased. But, Mr Kapoor does not think that the telecom party [...]

According to the sector’s watchdog Telecom Regulatory Authority of India (TRAI), as many as 19.1 million new connections were added during the month to take the net subscriber base to 562.21 million and the tele-density to an impressive 47.89 per cent.
“Total broadband subscriber base has increased from 7.57 million in November 2009 to 7.83 million [...]

Telecom New Zealand is planning to propose participation in the government’s plans to develop an ultrafast national fibre broadband network. The government is to invest more than $1 billion in the network, which will be divided into 33 regions.
The state-owned Crown Fibre Holdings will go through the proposals from potential partners, which are required to [...]

People have always been apprehensive about telecom towers in their areas, along with the person who rent the space for telecom towers.Noise pollution from towers originate when the power supply is disrupted and they switch to generators.
Because of   few public interest litigations. Pollution Control Board (TNPCB) has decided to inspect telecom towers.
According to Standards , ”Seventy-five decibels [...]

A SIM card issued in your name may be in the hands of a stranger, perhaps a criminal or even Maoist leader Kishanji. Goaded by
cut-throat competition, a section of telecom service providers is encouraging distributors to sell preactivated SIM cards
, despite a strict no-no by Trai, thereby allowing terrorists and criminals to exploit a security [...]

Introduction
This document takes you through a step-by-step procedure for upgrading your Cisco 800 Series Router. While an 800 series runs Cisco IOS® software like other Cisco routers, the ROM monitor (TinyROM) and some instructions are slightly different.
Note: If you have a Cisco 806, 826, 827, or 828 series router, see Upgrading Cisco IOS Software [...]