HomeinetMore than 80 Cisco products vulnerable to FragmentSmack

More than 80 Cisco products vulnerable to FragmentSmack

Cisco is investigating its products and services to see which ones use Linux kernel version 3.9 or earlier, which is vulnerable to the FragmentSmack denial-of-service bug.

The internet giant has already published a list of more than 80 of its products that appear to be vulnerable, and while the investigation is ongoing, it expects to release the relevant security updates by February 2019.

More than 80 Cisco products vulnerable to FragmentSmack

The products currently being tested by Cisco are in the routing and switching category, designed for enterprises and internet service providers. More specifically, the company tests the Application Policy Infrastructure Controller Enterprise Module (APIC-EM). APIC-EM enables automated and bulk device management.

Until these security updates are released by Cisco, the company suggests that customers check the documentation for each device for possible safer alternative modes of operation. Device administrators may be able to implement restrictive measures, such as access control lists (ACLs).

The FragmentSmack vulnerability, also known as CVE-2018-5391, allows unauthorized attackers to increase processor utilization to the maximum, rendering the device unresponsive. This is possible due to an inadequate algorithm used by the Linux kernel 3.9 (or earlier) to reassemble IPv4 and IPv6 packets.

Some of the routers that Cisco has already confirmed to be vulnerable are the following:

  • Cloud Services Platform 2100
  • Tetration Analytics
  • vEdge 100 Series Routers
  • vEdge 1000 Series Routers
  • vEdge 2000 Series Routers
  • vEdge 5000 Series Routers
  • vEdge Cloud Router Platform
  • ACI Virtual EdgeApplication Policy Infrastructure Controller (APIC)
  • DNA Center
  • iOS XE Software
  • IOx Fog Director
  • MDS 9000 Series Multilayer Switches
  • Network Assurance Engine
  • Nexus 3000 Series Switches
  • Nexus 7000 Series Switches
  • Nexus 9000 Series Fabric Switches – ACI mode
  • Nexus 9000 Series Switches – Standalone, NX-OS mode
  • ACI Virtual Edge
  • Application Policy Infrastructure Controller (APIC)
  • DNA CenterIOS XE Software
  • IOx Fog Director
  • MDS 9000 Series Multilayer Switches
  • Network Assurance Engine
  • Nexus 3000 Series Switches
  • Nexus 7000 Series Switches
  • Nexus 9000 Series Fabric Switches – ACI mode
  • Nexus 9000 Series Switches – Standalone, NX-OS mode
  • Aironet 1560 Series Access Points
  • Aironet 1815 Series Access Points
  • Aironet 2800 Series Access Points
  • Aironet 3800 Series Access Points
  • Mobility Services EngineWireless LAN Controller

The complete list along with future devices that Cisco will be mentioning can be found here.

 

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS