Cisco announced multiple security advisories

Last week, Cisco announced more security advisories regarding multiple possible vulnerabilities for range of it’s product. I will post here just a short summary about this advisories and provide you with the links to the full descriptions of the possible problems:

October 14, 2009 – Cisco Unified Presence Denial of Service Vulnerabilities

Cisco Unified Presence contains two denial of service (DoS) vulnerabilities that may cause an interruption to presence services. These vulnerabilities were discovered internally by Cisco, and there are no workarounds.

Cisco has released free software updates that address these vulnerabilities.

Read more…

October 15, 2009 – Multiple Vulnerabilities in Cisco Wireless LAN Controllers

Multiple vulnerabilities exist in the Cisco Wireless LAN Controller (WLC) platforms. This security advisory outlines the details of the following vulnerabilities:

Malformed HTTP or HTTPS authentication response denial of service vulnerability
SSH connections denial of service vulnerability
Crafted HTTP or HTTPS request denial of service vulnerability
Crafted HTTP or HTTPS request unauthorized configuration modification vulnerability
Cisco has released free software updates that address these vulnerabilities.

Read more…

October 19, 2009 – Cisco IOS Software Tunnels Vulnerability

Cisco devices running affected versions of Cisco IOS Software are vulnerable to a denial of service (DoS) attack if configured for IP tunnels and Cisco Express Forwarding.

Cisco has released free software updates that address this vulnerability.

Read more…

October 15, 2009 – Cisco IOS Software Authentication Proxy Vulnerability

Cisco IOS® Software configured with Authentication Proxy for HTTP(S), Web Authentication or the consent feature, contains a vulnerability that may allow an unauthenticated session to bypass the authentication proxy server or bypass the consent webpage.

Cisco has released free software updates that address this vulnerability.

There are no workarounds that mitigate this vulnerability.

Read more…

October 19, 2009 – Cisco IOS Software Internet Key Exchange Resource Exhaustion Vulnerability

Cisco IOS® devices that are configured for Internet Key Exchange (IKE) protocol and certificate based authentication are vulnerable to a resource exhaustion attack. Successful exploitation of this vulnerability may result in the allocation of all available Phase 1 security associations (SA) and prevent the establishment of new IPsec sessions.

Cisco has released free software updates that address this vulnerability.

Read more…

CCIE Routing and Switching Exam Certification Guide, 4th Edition

I just received the news that Cisco Press will release on 19th of November 2009, the 4th edition of  CCIE Routing and Switching Exam Certification Guide by Wendell Odom, Rus Healy and Denise Donohue.

A brief description from the Cisco Press site:

CCIE-RS-Cert-Guide-4th-Edition“The CCIE Routing and Switching certification is the most respected certification in the industry. The successful CCIE candidate must understand a broad range of network technologies that includes OSI model, bridging, LAN switching, IP and IP Routing protocols, multicast, WAN technologies, and performance management. The exam is notoriously difficult and CCIE candidates must first pass a qualifying written exam. The CCIE Routing and Switching Exam Certification Guide, Fourth Ed., covers all of the topics of the 4.0 written exam. In this updated edition there are content and alignment changes based on the revised v4.0 exam. The newest edition includes 300 pages of new content covering the following topics:

Network optimization

Troubleshooting

BGP routing policies

Expanded QoS coverage

Expanded WAN coverage

Expanded multicast coverage

Expanded MPLS coverage

IPv6 redistribution”

Currently you can pre-order the book and it will be delivered when published. If you are lucky enough to live in U.S. you can have it shipped for free.

Price and full details about this product can be found on the Cisco Press site.

Cisco acquire TANDBERG (for $3 billion)

Cisco today announced a definitive agreement for Cisco to launch a recommended voluntary cash offer to acquire TANDBERG (OSLO: TAA.OL).  TANDBERG, based in Oslo, Norway, and New York, is a global leader in video communications, including a broad range of world-class video endpoint and network infrastructure solutions with intercompany and multi-vendor interoperability. With this proposed acquisition, Cisco will expand its collaboration portfolio to offer more solutions to a greater number of customers, further accelerating market adoption globally.

Under the terms of the agreement, Cisco will commence a cash tender offer to purchase all the outstanding shares of TANDBERG for 153.5 Norwegian Kroner per share for an aggregate purchase price of approximately $3.0 billion.  This represents an 11.0% premium to the previous day closing price of TANDBERG’s stock, and a 25.2% premium to the 3-month volume weighted average closing price for TANDBERG’s stock.  The proposal was recommended unanimously by TANDBERG’s board of directors.

Source: Cisco.com

A world without wireless

Funny video about a world in which wireless would not exist. Sometimes I’m also complaining about slow access over wireless, errors or possible security holes, but looking at this material I realized that even with this gaps, this technology is doing a great job. I cannot imagine a world without it.

This video appear in celebration of the recently approved 802.11n standard. Also you can visit Cisco’s website Your Ideas in Motion where you can find white papers that provide an overview of the 802.11n standard, 802.11n competitive performance test results and collaborative testing with Cisco and Intel.