4 ms·
Can somebody more familiar with Cisco products look at the list and break this down a bit? Are these mostly edge-of-network devices, or are these big switches t
by seldo 13y ago
Can somebody more familiar with Cisco products look at the list and break this down a bit? Are these mostly edge-of-network devices, or are these big switches that tons of traffic run through?
Does being vulnerable to Heartbleed necessarily mean traffic through these boxes is vulnerable?
- dmix 13y agoThat depends, can the routers be accessed remotely over WAN? If so an admin password might pop up in memory scans allowing a compromise. From there remote software can be downloaded to the router, potentially allowing snooping/mirroring of traffic. But it's likely most of the them (ie the important ones) are behind local firewalls and VPNs.
- kyrra 13y agoExactly. Most affected products will be management interfaces for these devices. From my experience, enterprise type products direct you to put management ports on protected networks. IT people don't always follow this, but it's at least the recommendation.
- rdl 13y agoExcept, uh, their VPN client software :) And a lot of their WebEx, VoIP and VTC, which will be accessible either entirely within the organization, or on public networks. Looks like most of their actual routers and stuff are not affected, which is unsurprising -- they SSH, not SSL, and it's unlikely they'd be running OpenSSL 1.0.1.
- jlgaddis 13y ago> Are these mostly edge-of-network devices, or are these big switches that tons of traffic run through? IOS routers and ASA firewalls are on the "not affected" list. Those are what you'd find in most SMBs. IOS-XR and NX-OS are affected, however. This software runs on the BFRs like you'd see in major ISPs and large networks. > Does being vulnerable to Heartbleed necessarily mean traffic through these boxes is vulnerable? I'm speculating but based on what I know about Cisco gear, I'm gonna have to say no. At most, you'd get the same stuff you'd get from a server: the private keys, login credentials, copies of the configuration, etc. -- anything that's handled by the control plane of the routers, basically. The frames/packets passing through them are handled by ASICs and are never copied to the memory used by the CPU, AIUI. Assuming best practices are followed, a random attacker would never be able to establish a connection (e.g. to 443/TCP) anyways, which would mitigate the risk. In a properly managed network, access to the router itself is highly restricted by ACLs and such.