BugTraq
Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 10 2007 11:05AM
Damir Rajnovic (gaus cisco com) (1 replies)
Hello,

Cisco PSIRT is aware of the three videos IRM Plc. published on their
web site at <http://www.irmplc.com/index.php/153-Embedded-Systems-Security>.

Cisco and IRM agree that the videos do not demonstrate or represent a
vulnerability in Cisco IOS. Specifically, the code to manipulate
Cisco IOS could be inserted only under the following conditions:

- Usage of the debugger functionality present in IOS

- Having physical access to the device

- Already logged in at the highest privilege level on the device.

IRM approached Cisco PSIRT with this information prior to its public
release and Cisco has confirmed the information provided is a
proof-of-concept that third party code could be inserted under these
specific conditions.

Regards,

Gaus

==============
Damir Rajnovic <psirt (at) cisco (dot) com [email concealed]>, PSIRT Incident Manager, Cisco Systems
<http://www.cisco.com/go/psirt> Telephone: +44 7715 546 033
200 Longwater Avenue, Green Park, Reading, Berkshire RG2 6GB, GB
==============
There are no insolvable problems.
The question is can you accept the solution?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (Darwin)

iD8DBQFHDLHz8NUAbBmDaxQRAly/AJsGBSdnSVUeVvLmbM/wgq93w7d68ACgjQem
Pl0BqLrdWvvU5KZ/jUCRC0g=
=moHz
-----END PGP SIGNATURE-----

[ reply ]
Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 11 2007 07:25PM
Halvar Flake (halvar flake sabre-security com) (2 replies)
RE: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 10 2007 10:52PM
Andy Davis (andy davis irmplc com) (1 replies)
Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 12 2007 06:32AM
Halvar Flake (halvar flake sabre-security com) (1 replies)
RE: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 11 2007 07:32AM
Andy Davis (andy davis irmplc com) (1 replies)
Re: Cisco PSIRT response on IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Oct 12 2007 12:57PM
Roman Medina-Heigl Hernandez (roman rs-labs com) (1 replies)


 

Privacy Statement
Copyright 2010, SecurityFocus