IOS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 03:04 PM - edited 03-13-2019 05:44 PM
Hi Team ,
I have ISR router running "isr4300-universalk9.03.16.04b.S.155-3.S4b-ext.SPA.bin" below are the vulnerabilities found can any one suggest the solution for the same.
CVE-1999-0524 -- ICMP Timestamp Request
- Labels:
-
Routing
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 03:44 PM
Hello,
You can block this traffic from internal to out in your network
you can use ACL to block it:
check this exemple for icmp: https://community.cisco.com/t5/switching/acl-for-icmp/td-p/1053521
check this exemple for ntp: https://community.cisco.com/t5/routing/restrict-ntp-access/td-p/861842
Regards
*** Rate All Helpful Responses ***
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 03:52 PM
Thanks for the replay .
can you please help me to know whether this vulnerabilities are hitting on the running IOS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 04:11 PM - edited 03-12-2019 04:13 PM
Hello,
ICMP is very dangerous for DDoS or DoS: A distributed-denial-of-service, or DDoS, attack is the bombardment of simultaneous data requests to a central server. The attacker generates these requests from multiple compromised systems.
In doing so, the attacker hopes to exhaust the target’s Internet bandwidth and RAM. The ultimate goal is to crash the target’s system and disrupt its business.
Check it: https://www.cisco.com/c/en/us/products/security/what-is-a-ddos-attack.html
NTP: In summary, the attack is based on processing NTP Mode 7 requests from NTP clients that may elicit huge responses. While the requests are small (for example, in case of Mode 7, the request is only 8 bytes long), the response can grow up to 5,500 times that size due to amplification.
All of this vulnerabilities can crash your router requesting lot of RAM, CPU and BANDWIDTH.
If you have a NTP Service configured on your router and you dont tunning it, maybe you has a vulnerability.
If you have any interface UP/UP allowed to external (internet), you can receive a DoS or DDoS attack.
*** Rate All Helpful Responses ***
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 07:24 PM
Hi Jaderson Pessoa ,
Thanks for the update .
I have checked the same vulnerabilities in cisco portal but coudn't found this CVE ID'S are hitting the running IOS .There are lot of vulnerabilities are present in the current running ver except the mentioned CVE ID.
can you please clarify the same.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-13-2019 04:33 AM
as i said, if you have this services configured without any parameter, you have a possible problem.
Regards,
*** Rate All Helpful Responses ***
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2019 04:15 PM
Thanks in advance.
*** Rate All Helpful Responses ***
