RE: Cisco Security Advisory: CBOS Web-based Configuration Utility Vulnerability

From: Snow, Corey (CSNOWat_private)
Date: Fri Aug 24 2001 - 14:31:17 PDT

  • Next message: Daniel Kasmeroglu: "Java Plugin 1.4 with JRE 1.3 -> Ignores certificates."

    There is one other thing about the Cisco DSL router issue that I'd like to
    point out- maybe it's obvious to everyone, but I haven't seen any mention of
    it in the various discussions and advisories- as near as I can tell, a Cisco
    675 (the only one I have) which is operating in Bridging mode is not
    vulnerable to this flaw.
    
    I assume that I haven't experienced any problems with my 675 because I'm
    operating in bridging mode, which of course means that the 675 doesn't have
    an IP address of its own per se, and therefore can't be talked with directly
    in the sense of trying to talk to an HTTP port.
    
    I don't know about the other products mentioned in the various
    discussions/advisories.
    
    Regards,
    
    Corey Snow
    
    #########################################################
    The information contained in this e-mail and subsequent attachments may be privileged, 
    confidential and protected from disclosure.  This transmission is intended for the sole 
    use of the individual and entity to whom it is addressed.  If you are not the intended 
    recipient, any dissemination, distribution or copying is strictly prohibited.  If you 
    think that you have received this message in error, please e-mail the sender at the above 
    e-mail address.
    #########################################################
    



    This archive was generated by hypermail 2b30 : Fri Aug 24 2001 - 15:56:10 PDT