Cisco experts dish on 'Heartbleed' IP security vulnerability

April 28, 2014
The company has also issued an official, downloadable Security Advisory bulletin.

In the following Youtube video, posted April 25, IP security experts Craig Williams and Jaeson Schultz of Cisco discuss the Heartbleed online security vulnerability and developments in handling the bug since its public disclosure two weeks ago. Cisco has also issued an official, downloadable "Security Advisory" bulletin entitled, OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products.

"Multiple Cisco products incorporate a version of the OpenSSL package affected by a vulnerability that could allow an unauthenticated, remote attacker to retrieve memory in chunks of 64 kilobytes from a connected client or server. The vulnerability is due to a missing bounds check in the handling of the Transport Layer Security (TLS) heartbeat extension," summarizes the advisory note.

Related: Target stores' data breach exposes major security threat of POS malware

The note continues, " An attacker could exploit this vulnerability by implementing a malicious TLS or Datagram Transport Layer Security (DTLS) client, if trying to exploit the vulnerability on an affected server, or a malicious TLS or DTLS server, if trying to exploit the vulnerability on an affected client. An exploit could send a specially crafted TLS or DTLS heartbeat packet to the connected client or server. An exploit could allow the attacker to disclose a limited portion of memory from a connected client or server for every heartbeat packet sent. The disclosed portions of memory could contain sensitive information that may include private keys and passwords."

Among the affected products and services which have had their exposure to the Heartbleed vulnerability confirmed are the Cisco Video Surveillance 3000/4000/6000/7000 Series IP cameras; its 4300E/4500E High-Definition IP cameras; and its PTZ IP cameras. A full -- and extensive -- list of affected and potentially affected products and services is available in the Security Advisory bulletin.

View/Download Cisco's 'OpenSSL Heartbeat Extension Vulnerability' Security Advisory

Sponsored Recommendations

Cat 6A Frequently Asked Questions

April 29, 2024
At CommScope we know about network change and the importance of getting it right. Conclusion Category 6A cabling and connectivity.

Cat 6A Hard Facts

Aug. 3, 2022
At CommScope we know about network change and the importance of getting it right. Conclusion Category 6A cabling and connectivity.

What you need to know about 6A cabling

Aug. 3, 2022
Did you know that Category 6A cable is the best choice for structured cabling?

Why CommScope 6A?

Nov. 7, 2022
Inside buildings and across campuses, network demands and economics are changing. As applications like IoT, 10GBASE-T, multigigabit Wi-Fi 6/6E/7 and PoE++ become more common, ...