I thought this alert was worth passing along. It seems by turning off IPv6 you minimize exposure to this attack.
National Cyber Alert System
Technical Cyber Security Alert TA05-210A
Cisco IOS IPv6 Vulnerability
Original release date: July 29, 2005
Last revised: --
Source: US-CERT
Systems Affected
* Cisco IOS devices with IPv6 enabled
For specific information, please see the Cisco Advisory.
Overview
Cisco IOS IPv6 processing functionality contains a vulnerability that
could allow an unauthenticated, remote attacker to execute arbitrary
code or cause a denial of service.
Cisco IOS contains a vulnerability in the way IPv6 packets are
processed. US-CERT has not confirmed further technical details.
According to the Cisco Advisory, this vulnerability could be exploited
by an attacker on the same IP subnet:
Crafted packets from the local segment received on logical
interfaces (that is, tunnels including 6to4 tunnels) as well as
physical interfaces can trigger this vulnerability. Crafted packets
can not traverse a 6to4 tunnel and attack a box across the tunnel.
The crafted packet must be sent from a local network segment to
trigger the attack. This vulnerability can not be exploited one or
more hops from the IOS device.
US-CERT strongly recommends that sites running Cisco IOS devices
review the Cisco Advisory and upgrade as appropriate. We are tracking
this vulnerability as VU#930892.
II. Impact
This vulnerability could allow an unauthenticated, remote attacker on
the same IP subnet to execute arbitrary code or cause a denial of
service. The attacker may be able to take control of a vulnerable
device.
III. Solutions
Upgrade
Upgrade to a fixed version of IOS. Please see the Software Versions
and Fixes section of the Cisco Advisory for details.
Disable IPv6
From the Cisco Advisory:
In networks where IPv6 is not needed, disabling IPv6 processing on
an IOS device will eliminate exposure to this vulnerability. On a
router which supports IPv6, this must be done by issuing the
command "no ipv6 enable" and "no ipv6 address" on each interface.
Appendix A. Vendor Information
Cisco Systems, Inc.
Cisco Systems, Inc. has released a security advisory regarding a
vulnerability which was disclosed on July 27, 2005 at the Black Hat
security conference. Security advisory is available at:
http://www.cisco.com/warp/public/707/cisco-sa-20050729-ipv6.shtml
For up-to-date information on security vulnerabilities in Cisco
Systems, Inc. products, visit http://www.cisco.com/go/psirt.
Appendix B. References
* US-CERT Vulnerability Note VU#930892 -
<http://www.kb.cert.org/vuls/id/930892>
* Cisco Security Advisory: IPv6 Crafted Packet Vulnerability -
<http://www.cisco.com/en/US/products/products_security_advisory091
86a00804d82c9.shtml>
_________________________________________________________________
Information regarding this vulnerability was primarily provided by
Cisco Systems, who in turn acknowledge the disclosure of this
vulnerability at the Black Hat USA 2005 Briefings.
_________________________________________________________________
Feedback can be directed to US-CERT Technical Staff. Send mail to
<cert@cert.org> with "TA05-210A feedback VU#930892" in the subject.
_________________________________________________________________
The most recent version of this document is available at:
<http://www.us-cert.gov/cas/techalerts/TA05-210A.html>
_________________________________________________________________
Produced 2005 by US-CERT, a government organization.
_________________________________________________________________
Terms of use:
<http://www.us-cert.gov/legal.html>
_________________________________________________________________
Revision History
July 29, 2005: Initial release
3g 4g android apple asterisk at&t att broadband call center cisco communications conference consumer electronics crm expo facebook fcc gadget google ims ip communications ipad iphone ipod itexpo microsoft Microsoft sip skype technology tmc tmcnet unified communications verizon video voip vonage wifi wireless yahoo
- 4G (1002)
- AT&T (1365)
- Amazon (104)
- Android (161)
- Apple (1375)
- Avaya (545)
- Blackberry (720)
- CES (17)
- Call Center (1144)
- Cisco (796)
- Cloud Computing (125)
- Communications Developer (647)
- Conference (366)
- Consumer Electronics (1880)
- E-Commerce (642)
- FCC (1185)
- Facebook (250)
- Fax (346)
- Financial (581)
- Gadget (980)
- Google (1248)
- Green (300)
- HD Voice (222)
- HTML5 (46)
- IP Communications (2926)
- M2M (127)
- MSP (2)
- MWC (26)
- Marketing (38)
- Merger/Acquisition (277)
- Microsoft (1374)
- Musings (84)
- Networking (66)
- Nortel (486)
- Optical (192)
- Patent (207)
- Personal (280)
- Podcast (104)
- Political (45)
- SaaS (228)
- Samsung (4)
- Satellite (115)
- Science (279)
- Search (202)
- Security (595)
- Smart Ecosystem (126)
- Smart Grid (144)
- Social Networking (670)
- Software Telco (1)
- Super WiFi (23)
- TMC Team (185)
- TMC Video (103)
- TMCnet (66)
- Technology (3846)
- Twitter (160)
- Ultrabook (22)
- Unified Communications (1495)
- Verizon (1145)
- Video (1318)
- Virtual Worlds (174)
- VoIP (3517)
- Vonage (408)
- Wearable Tech (1)
- WebRTC (8)
- Yahoo (353)
- iPad (70)
- May 2013
- April 2013
- March 2013
- February 2013
- January 2013
- December 2012
- November 2012
- October 2012
- September 2012
- August 2012
- July 2012
- June 2012
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- January 2006
- December 2005
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- April 2005
- March 2005
- February 2005
- January 2005
- December 2004
- November 2004
- October 2004
- September 2004
- August 2004
- July 2004
- June 2004
- May 2004
- April 2004






