ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Cisco admits numerous network vulnerabilities

Cisco has put out an advisory notice after finding security flaws in its Network Building Mediator products.

By Tom Brewster, 27 May 2010 at 13:11

Security

Cisco has put out a warning about numerous vulnerabilities in its Network Building Mediator (NBM) products that could lead to malicious parties taking complete control over affected devices.

The NBM connects a building’s operations with IT to help with a facility’s sustainability, energy consumption and efficiency.

In an advisory note, Cisco explained that certain security gaps allow unauthorised users to change a device’s configuration.

“A malicious user must authenticate as an existing user but does not need to have administrator privileges or know administrator credentials to modify device configuration,” the company noted.

Other vulnerabilities mean that interactions between an operator workstation and the Cisco Network Building Mediator could be intercepted by any willing person.

“A malicious user able to intercept the sessions could learn any credentials used during intercepted sessions (for administrators and non-administrators alike) and could subsequently take full control of the device,” Cisco explained.

Other threats include potential password theft and account data loss.

Specifically, all weaknesses affect the legacy Richards-Zeta Mediator 2500 product and Cisco Network Building Mediator NBM-2400 and NBM-4800 models as well as Mediator Framework software releases prior to 3.1.1.

The NBM is a version of the Richards-Zeta Mediator that has been adapted by Cisco.

Given that the “workarounds” offered by Cisco are somewhat limited, affected firms will want to get hold of the free software updates that the provider has issued to deal with the security holes.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement