navbarPDF
Strip_SecurityNotices

Cisco Security Response: Extensible Authentication Protocol Vulnerability

Document ID: 98727

http://www.cisco.com/warp/public/707/cisco-sr-20071019-eap.shtml

Revision 1.5

Last Updated 2007 December 03 0300 UTC (GMT)

For Public Release 2007 October 19 1600 UTC (GMT)


Please provide your feedback on this document.


Contents

Cisco Response
Additional Information
Revision History
Cisco Security Procedures

Cisco Response

This is the Cisco PSIRT response to a presentation that was delivered by Laurent Butti, Julien Tinnès and Franck Veysset of France Telecom Group at Hack.lu on October 19th, 2007.

The presentation identifies a vulnerability in Cisco's implementation of Extensible Authentication Protocol (EAP) that exists when processing a crafted EAP Response Identity packet. This vulnerability affects several Cisco products that have support for wired or wireless EAP implementations.

The Cisco PSIRT team greatly appreciates the opportunity to work with researchers on security vulnerabilities, and we welcome the opportunity to review and assist in product reports.

This vulnerability is documented in the following Cisco bug IDs:

This Cisco Security Response is available at the following link: http://www.cisco.com/warp/public/707/cisco-sr-20071019-eap.shtml.

Additional Information

As described in RFC3748 leavingcisco.com, EAP is an authentication framework that supports multiple authentication methods. Typically, EAP runs directly over data link layers, such as Point-to-Point Protocol (PPP) or IEEE 802, without requiring IP.

Vulnerable Products

This vulnerability affects both wired and wireless implementation on Cisco devices.

EAP is not configured by default on any of these Cisco devices.

The following Cisco products support Wireless EAP and are affected by this vulnerability:

The following Cisco products support Wired EAP and are affected by this vulnerability.

There are no workarounds for this vulnerability on wired or wireless implementations of EAP.

Successful exploitation of the vulnerability on either the wired or wireless device will result in a reload of the device. Repeated exploitation could result in a sustained DoS attack.

The list below describes the affected trains and the first fixed release:

Wireless EAP - CSCsj56438

Affected Release

First Fixed Releases

12.3.JA

Vulnerable;

For AP1100s & AP1200s migrate to 12.3(8)JEC or later.

For AP1130, AP1240, AP1310 & AP1410 migrate 12.4(10b)JA or later.

12.3.JEA

Vulnerable; migrate to 12.3(8)JEC or later

12.3.JEB

Vulnerable; migrate to 12.3(8)JEC or later

12.3.JEC

12.3(8)JEC or later

12.4.JA

12.4(10b)JA or later

12.4.JX

Vulnerable; migrate to 12.4(10b)JA or later

12.4.XW

12.4.XW5 or later

WLSM (All releases)

2.3.2 or later

Wired EAP (Cisco IOS) - CSCsb45696

Affected Major Release

First Fixed Releases

12.1

12.1(27b)E2 or later

12.1(22)EA6 or later

12.1(26)EB2 or later

12.2

12.2(18)EW6 or later

12.2(18)S13 or later

12.2(18)SXF9 or later

12.2.18-ZY1 or later

12.2(20)S13 or later

12.2(25)EWA4 or later

12.2(25)EX or later

12.2(25)FX or later

12.2(25)SED or later

12.2(25)SG or later

12.2(31)SB6 or later

12.2(33)SRA4 or later

Wired EAP (Cisco CatOS) - CSCsc55249

Affected Major Release

First Fixed Releases

6.x

Vulnerable; migrate to 7.x or 8.x

7.x

7.6(23) or later

8.x

8.5(9) or later

8.6(1) or later

No other Cisco IOS major release trains are known to be affected by this vulnerability.

For more information on the terms "releases" and "trains," consult the following URL:

http://www.cisco.com/warp/public/620/1.html

Products Confirmed Not Vulnerable

The following Cisco products that support the EAP framework have been confirmed as not affected by this vulnerability:

THIS SECURITY NOTICE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

A stand-alone copy or paraphrase of the text of this Security Notice that omits the distribution URL in the following section is an uncontrolled copy, and may lack important information or contain factual errors.

THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.

Revision History

Revision 1.5

2007-December-03

Updated Wireless EAP software table with information for WLSM and Cisco IOS Software Release 12.4.XW. Added Cisco Unified Communications 500 Series under Vulnerable Products section.

Revision 1.4

2007-October-30

Revised product heading and added a new product line under Vulnerable Products section. Added WLSM to the Wireless EAP table.

Revision 1.3

2007-October-30

Updated software tables for Wireless EAP and Wireless EAP (CatOS).

Revision 1.2

2007-October-29

Updated software tables for Wireless EAP and Wireless EAP (CatOS).

Revision 1.1

2007-October-26

Updated software tables for Wireless EAP and Wireless EAP (CatOS); Removed Cisco 521 Wireless Express Access Point from Products Confirmed Not Vulnerable.

Revision 1.0

2007-October-19

Initial public release.

Cisco Security Procedures

Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.


Toolbar


Updated: Dec 03, 2007Document ID: 98727