Cisco Response
Additional Information
Revision History
Cisco Security Procedures
This is a Cisco response to an advisory published by FX of Phenoelit
posted as of September 13, 2006, at
http://www.securityfocus.com/archive/1/445896/30/0/threaded
,
and entitled "Cisco Systems IOS VTP multiple vulnerabilities".
We would like to thank FX and Phenoelit Group for reporting these vulnerabilities to us.
We greatly appreciate the opportunity to work with researchers on security vulnerabilities, and welcome the opportunity to review and assist in security vulnerability reports against Cisco products.
These vulnerabilities are addressed by Cisco Bug IDs:
VLAN Trunking Protocol (VTP) is a Layer 2 messaging protocol that maintains VLAN configuration consistency by managing the addition, deletion, and renaming of VLANs on a network-wide basis. When you configure a new VLAN on one VTP server, the VLAN configuration information is distributed via the VTP protocol through all switches in the domain. This reduces the need to configure the same VLAN everywhere. VTP is a Cisco-proprietary protocol that is available on most of the Cisco Catalyst series products in both Cisco IOS and Cisco CatOS system software.
Products affected by these vulnerabilities:
Products not affected by these vulnerabilities:
To determine the VTP mode on the switch, log in to the device and issue the show vtp status command on an IOS device or the show vtp domain command on a CatOS device. Switches that show either "server" or "client" as the VTP operating mode are affected by these vulnerabilities.
An example is shown below for Cisco IOS software with VTP operating in "server" mode:
ios_switch#show vtp status VTP Version : 2 Configuration Revision : 0 Maximum VLANs supported locally : 1005 Number of existing VLANs : 5 VTP Operating Mode : Server VTP Domain Name : test VTP Pruning Mode : Disabled VTP V2 Mode : Enabled VTP Traps Generation : Disabled MD5 digest : <removed> Configuration last modified by 0.0.0.0 at 3-1-93 04:02:09 ios_switch#
An example is shown below for Cisco CatOS with VTP operating in "server" mode:
catos_switch> (enable) show vtp domain
Version : running VTP1 (VTP3 capable)
Domain Name : test Password : not configured
Notifications: disabled Updater ID: 0.0.0.0
Feature Mode Revision
-------------- -------------- -----------
VLAN Server 2
Pruning : disabled
VLANs prune eligible: 2-1000
catos_switch> (enable)
Example from Cisco CatOS:ios_switch#show vtp status VTP Version : 2 Configuration Revision : -2147483648 Maximum VLANs supported locally : 1005 Number of existing VLANs : 17 VTP Operating Mode : Client VTP Domain Name : psirt VTP Pruning Mode : Disabled VTP V2 Mode : Disabled VTP Traps Generation : Disabled MD5 digest : <removed> Configuration last modified by 0.0.0.0 at 3-1-93 00:10:07 ios_switch#
Applying a VTP domain password to the VTP domain will prevent spoofed VTP summary advertisement messages from advertising 0x7FFFFFFF as a configuration revision number. Refer to http://www.cisco.com/en/US/products/hw/switches/ps646/products_configuration_guide_chapter09186a00801cdf36.html#1035247 for further information on setting VTP domain passwords.catos_switch# (enable) show vtp domain Version : running VTP1 (VTP3 capable) Domain Name : psirt Password : not configured Notifications: disabled Updater ID: 0.0.0.0 Feature Mode Revision -------------- -------------- ----------- VLAN Server -2147483648 Pruning : disabled VLANs prune eligible: 2-1000
For further information on VTP, please refer to http://www.cisco.com/en/US/tech/tk389/tk689/technologies_tech_note09186a0080094c52.shtml.
For further information on Layer 2 security practices, please refer to http://www.cisco.com/en/US/netsol/ns340/ns394/ns171/ns128/networking_solutions_white_paper09186a008014870f.shtml#wp998892.
THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.
|
Revision 1.0 |
2006-September-13 |
Initial public release. |
Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.
| Updated: Sep 13, 2006 | Document ID: 71306 |