navbarPDF
Strip_SecurityNotices

Cisco Security Response: Cisco VLAN Trunking Protocol Vulnerabilities

Document ID: 71306

http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtml

Revision 1.0

For Public Release 2006 September 13 1700 UTC (GMT)


Please provide your feedback on this document.


Contents

Cisco Response
Additional Information
Revision History
Cisco Security Procedures

Cisco Response

This is a Cisco response to an advisory published by FX of Phenoelit posted as of September 13, 2006, at http://www.securityfocus.com/archive/1/445896/30/0/threaded leavingcisco.com, and entitled "Cisco Systems IOS VTP multiple vulnerabilities".

We would like to thank FX and Phenoelit Group for reporting these vulnerabilities to us.

We greatly appreciate the opportunity to work with researchers on security vulnerabilities, and welcome the opportunity to review and assist in security vulnerability reports against Cisco products.

These vulnerabilities are addressed by Cisco Bug IDs:

Additional Information

VLAN Trunking Protocol (VTP) is a Layer 2 messaging protocol that maintains VLAN configuration consistency by managing the addition, deletion, and renaming of VLANs on a network-wide basis. When you configure a new VLAN on one VTP server, the VLAN configuration information is distributed via the VTP protocol through all switches in the domain. This reduces the need to configure the same VLAN everywhere. VTP is a Cisco-proprietary protocol that is available on most of the Cisco Catalyst series products in both Cisco IOS and Cisco CatOS system software.

Products affected by these vulnerabilities:

Products not affected by these vulnerabilities:

To determine the VTP mode on the switch, log in to the device and issue the show vtp status command on an IOS device or the show vtp domain command on a CatOS device. Switches that show either "server" or "client" as the VTP operating mode are affected by these vulnerabilities.

An example is shown below for Cisco IOS software with VTP operating in "server" mode:

ios_switch#show vtp status  
VTP Version                     : 2
Configuration Revision          : 0
Maximum VLANs supported locally : 1005
Number of existing VLANs        : 5
VTP Operating Mode              : Server
VTP Domain Name                 : test
VTP Pruning Mode                : Disabled
VTP V2 Mode                     : Enabled
VTP Traps Generation            : Disabled
MD5 digest                      : <removed> 
Configuration last modified by 0.0.0.0 at 3-1-93 04:02:09
ios_switch#

An example is shown below for Cisco CatOS with VTP operating in "server" mode:

catos_switch> (enable) show vtp domain
Version      : running VTP1 (VTP3 capable)
Domain Name  : test              Password  : not configured
Notifications: disabled          Updater ID: 0.0.0.0
    
Feature        Mode           Revision
-------------- -------------- -----------
VLAN           Server         2          

Pruning             : disabled
VLANs prune eligible: 2-1000
catos_switch> (enable)

For further information on VTP, please refer to http://www.cisco.com/en/US/tech/tk389/tk689/technologies_tech_note09186a0080094c52.shtml.

For further information on Layer 2 security practices, please refer to http://www.cisco.com/en/US/netsol/ns340/ns394/ns171/ns128/networking_solutions_white_paper09186a008014870f.shtml#wp998892.

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Revision History

Revision 1.0

2006-September-13

Initial public release.

Cisco Security Procedures

Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.


Toolbar

All contents are Copyright © 2006-2007 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.


Updated: Sep 13, 2006Document ID: 71306