Cisco PIX and CBAC Fragmentation Attack
BID:690
Info
Cisco PIX and CBAC Fragmentation Attack
| Bugtraq ID: | 690 |
| Class: | Serialization Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 1998 12:00AM |
| Updated: | Aug 18 1998 12:00AM |
| Credit: | This vulnerability was discovered by Robert Ståhlbrand <[email protected]> and reported to BugTraq on 18 August 1998. |
| Vulnerable: |
Cisco PIX Firewall 4.2.1 Cisco IOS 12.0T Cisco IOS 12.0 Cisco IOS 11.3T Cisco IOS 11.2P |
| Not Vulnerable: | |
Discussion
Cisco PIX and CBAC Fragmentation Attack
Both the Cisco PIX Firewall software as the Context-based Access Control (CBAC) feature of Cisco's IOS Firewall Feature Set do not properly check non-initial fragmented IP packets. Although the non-initial fragmented IP packets might belong to session which would normally be blocked, they are forwarded to the destination host. This may lead to a denial of services (DOS) attack due to the exhaustion of resources required to keep track of the fragmented IP packets.
The problem can be fixed by keeping track of the sessions that fragmented IP packets belong to and by blocking non-initial fragmented IP packets for which no initial packet has been seen.
The DOS attack can easily be carried out by publically available tools.
Both the Cisco PIX Firewall software as the Context-based Access Control (CBAC) feature of Cisco's IOS Firewall Feature Set do not properly check non-initial fragmented IP packets. Although the non-initial fragmented IP packets might belong to session which would normally be blocked, they are forwarded to the destination host. This may lead to a denial of services (DOS) attack due to the exhaustion of resources required to keep track of the fragmented IP packets.
The problem can be fixed by keeping track of the sessions that fragmented IP packets belong to and by blocking non-initial fragmented IP packets for which no initial packet has been seen.
The DOS attack can easily be carried out by publically available tools.
Exploit / POC
Cisco PIX and CBAC Fragmentation Attack
see discussion
see discussion
Solution / Fix
Cisco PIX and CBAC Fragmentation Attack
Solution:
The vulnerability on the PIX Firewall has been assigned Cisco bug ID CSCdk36273. Version 4.2(2) of the PIX Firewall software fixes the vulnerability and is available freely.
The vulnerability in the CBAC feature has been assigned Cisco bug ID CSCdk41516. The free software fix for the CBAC feature is targeted for releases 12.0(2) and 12.0(3)T.
Fixes can either be obtained through the support channel or by contacting a Cisco TAC as detailed in the advisory (see reference).
Solution:
The vulnerability on the PIX Firewall has been assigned Cisco bug ID CSCdk36273. Version 4.2(2) of the PIX Firewall software fixes the vulnerability and is available freely.
The vulnerability in the CBAC feature has been assigned Cisco bug ID CSCdk41516. The free software fix for the CBAC feature is targeted for releases 12.0(2) and 12.0(3)T.
Fixes can either be obtained through the support channel or by contacting a Cisco TAC as detailed in the advisory (see reference).
References
Cisco PIX and CBAC Fragmentation Attack
References:
References:
- Cisco Product Security Incident Response (Cisco Systems)