<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic snmp sig in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630202#M87986</link>
    <description>&lt;P&gt;Last "Patch Tuesday" there was a serious vulnerability reported for Microsoft that could be exploited via an SNMP buffer overflow.  But there does not seem to be a Cisco signature yet.  Is there any status on this?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:23:11 GMT</pubDate>
    <dc:creator>rwebster</dc:creator>
    <dc:date>2019-03-10T10:23:11Z</dc:date>
    <item>
      <title>snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630202#M87986</link>
      <description>&lt;P&gt;Last "Patch Tuesday" there was a serious vulnerability reported for Microsoft that could be exploited via an SNMP buffer overflow.  But there does not seem to be a Cisco signature yet.  Is there any status on this?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630202#M87986</guid>
      <dc:creator>rwebster</dc:creator>
      <dc:date>2019-03-10T10:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630203#M87987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Due to the nature of the vulnerability we are unable to create a signature with sufficient fidelity.  These types of vulnerabilities are best suited to end point security systems such as CSA and are unsuitable for network detection. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2006 22:52:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630203#M87987</guid>
      <dc:creator>rupadras</dc:creator>
      <dc:date>2006-12-20T22:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630204#M87988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add to the information, the signature status of the vulnerability can also be viewed on MySDN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/MySDN/Intelligence/searchThreats.x?currentPage=3&amp;amp;st=td&amp;amp;so=d" target="_blank"&gt;http://tools.cisco.com/MySDN/Intelligence/searchThreats.x?currentPage=3&amp;amp;st=td&amp;amp;so=d&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 02:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630204#M87988</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2006-12-21T02:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630205#M87989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am confused.  One post shows that you do have a signature, 5274.  But you say that this kind of attack is not suited to network detection?  This does not make sense to me.  It is my understanding that it is a buffer overflow. SNMP is often poorly compliant with RFC's but this is definately a network based issue and as a customer that owns IPS and not CSA it sounds like you are leaving us out on a limb.  This is exactly why we have Cisco IPS, that is to identify when someone uses a network based exploit to attack us.  If Cisco will not be emphasizing this kind of issue on IPS then perhaps we should be investigating a better solution.  This is a very disappointing and scary response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 14:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630205#M87989</guid>
      <dc:creator>rwebster</dc:creator>
      <dc:date>2006-12-21T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630206#M87990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but this link just describes the vulnerability, at least right now.  There does not seem to be any signature information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 15:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630206#M87990</guid>
      <dc:creator>rwebster</dc:creator>
      <dc:date>2006-12-21T15:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630207#M87991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I see the 5274 is not a signature.  But I need Cisco to figure this out.  If I need CSA, I really do need a different IPS.  CSA is not an option for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 15:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630207#M87991</guid>
      <dc:creator>rwebster</dc:creator>
      <dc:date>2006-12-21T15:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: snmp sig</title>
      <link>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630208#M87992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, here is what your competition has to say, below. They do have a signature.  If it is a single udp packet, why can't it be detected?  This could be slammer all over again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition Security focus claims to have an exploit.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.securityfocus.com/bid/21537/exploit" target="_blank"&gt;http://www.securityfocus.com/bid/21537/exploit&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"This bulletin covers an integer underflow vulnerability in Windows SNMP.  This underflow enables attackers to gain complete control of a remote machine with a single malformed UDP packet that is easily spoofed."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously you've pushed some buttons telling me to go buy something else. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 15:36:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snmp-sig/m-p/630208#M87992</guid>
      <dc:creator>rwebster</dc:creator>
      <dc:date>2006-12-21T15:36:39Z</dc:date>
    </item>
  </channel>
</rss>

