Public Safety and Emergency Preparedness Canada - Sécurité publique et Protection civile Canada
Skip all menus (access key: 2) Skip first menu (access key: 1)
Français Contact Us Help Search Canada Site
About us Policy Research Programs Newsroom
Public Safety and Emergency Preparedness Canada

INFORMATION FOR...
Citizens
Communities
Governments
Business
First responders
Educators
ALTERNATE PATHS...
A-Z index
Site map
Organization
OF INTEREST...
SafeCanada.ca
Tackling Crime
EP Week
Proactive disclosure


Printable versionPrintable version
Send this pageSend this page

Home Programs Emergency management Response CCIRC Analytical releases2 AV06-029: Cisco security response to: Cisco IOS GRE decapsulation vulnerability

Cisco security response to: Cisco IOS GRE decapsulation vulnerability

Number: AV06-029
Date: 07 September 2006

Purpose

The purpose of this advisory is to bring attention to a Cisco response to an advisory published by FX of Phenoelit posted as of September 06, 2006, at http://www.securityfocus.com/archive/1/445322/30/0/threaded, and entitled "Cisco Systems IOS GRE decapsulation fault".

Assessment

This vulnerability applies to Cisco routers running certain versions of the IOS software (see "Affected Products" section below).

Upon receiving a specially crafted GRE packet, depending on the data within a specific packet memory location, the GRE code will decapsulate a packet using the contents of referenced memory buffers. Only if the referenced memory buffers data decapsulates to a valid IPv4 packet will this packet be forwarded. Invalid IPv4 packets will be dropped at the router. This potentially could be used to bypass access-control lists on the router.

This issue is being tracked by the following Cisco bug IDs:

  • CSCuk27655 — GRE: make implementation RFC 2784 and RFC 2890 compliant
  • CSCea22552 — GRE: implementation of Reserved0 field not RFC2784 compliant
  • CSCei62762 — GRE: IP GRE Tunnel with Routing Present Bit not dropped

Although there are no public reports of active exploitation or proof-of-concept code, this type of vulnerability may lead to system compromise.

Affected products

- Vulnerable Products

  • Cisco IOS software 12.0, 12.1, and 12.2 based trains
  • All devices running affected versions of Cisco IOS software and configured with GRE IP or GRE IP multipoint tunnels

- Products Not Affected by This Vulnerability

  • Cisco IOS Software 12.3 and 12.4 based trains
  • Cisco IOS Software 12.0S release train, with a revision later than Cisco IOS Software Release 12.0(23)S, with CEF enabled (default behavior)

Suggested action

PSEPC recommends that system administrators test and apply the latest security update and/or mitigation strategy as indicated for their supported product versions. Please see the Cisco advisory below for complete details and instructions.

http://www.cisco.com/en/US/tech/tk827/tk369/
tsd_technology_security_response09186a008072cd7b.html#secpro

Note to readers

Canadian Cyber Incident Response Centre (CCIRC) collects information related to cyber threats to, and incidents involving, Canadian critical infrastructure. This allows us to monitor and analyze threats and to issue alerts, advisories and other information products. To report threats or incidents, please contact the Government Operations Centre (GOC) at (613) 991-7000 or goc-cog@psepc.gc.ca by e-mail.

Unauthorized use of computer systems and mischief in relation to data are serious Criminal Code offences in Canada. Any suspected criminal activity should be reported to local law enforcement organizations. The Royal Canadian Mounted Police (RCMP) National Operations Centre (N.O.C.) provides a 24/7 service to receive such reports or to redirect callers to local law enforcement organizations. The N.O.C. can be reached at (613) 993-4460. National security concerns should be reported to the Canadian Security Intelligence Service (CSIS) at (613) 993-9620.

For urgent matters or to report any incidents, please contact the Government Operations Centre at:

Phone: (613) 991-7000
Fax: (613) 996-0995
Secure Fax: (613) 991-7094
Email: goc-cog@psepc.gc.ca

For general information on critical infrastructure protection and emergency preparedness, please contact PSEPC's Public Affairs division at:

Telephone: (613) 944-4875 or 1-800-830-3118
Fax: (613) 998-9589
E-mail: communications@psepc.gc.ca

Top of Page
Last updated: 2006-09-07 Top of Page Important notices