|
Critical Unicode Flaw Undercuts Firewalls, Scanners |
|
Thursday, 31 May 2007 |
US-CERT reports that 92 security products by different vendors,
including Cisco, may have a serious security hole. Given these
products' market share, most businesses could be affected. The U.S. Computer Emergency Response Team is reporting
a network evasion technique that uses full-width and half-width unicode
characters to allow malware to evade detection by an IPS or firewall.
The vulnerability affects virtually every major firewall and intrusion
prevention system available, including products from Cisco Systems.
Given Cisco's major share of the market, at least for enterprise
routers and VPN and firewall equipment—according to Gartner, Cisco was
at the top of the heap with 66 percent of that market in 2006—that
means most businesses will be affected.
More info can be found at :
http://www.eweek.com/article2/0,1759,2130397,00.asp?kc=EWRSS03129TX1K0000614
|