Cisco Threat Defense Bulletin S669 September 20, 2012


CSIO banner left
Globe banner right


In This Issue
Important Notes
Supported Sensor Software Versions
Release Summary
New Vulnerability and Exploit Protections
Updated Vulnerability and Exploit Protections
Retired Signatures
Sensor Update Information
New Product Announcements
EoL/EoS Announcements
Security Research Library

Microsoft Bulletin Update
Cisco Security Intelligence Operations VoD

Cisco Remote Management Services for Security
Providing 24x7x365 remote security management, monitoring, and remediation for today's networks.

Did you know IPS customers already have Cisco IntelliShield search access?
IntelliShield banner
Register your free account here

Cisco Security Intelligence Operations
Threat Map
Identify, Analyze, Defend
Comprehensive threat intelligence, analysis, and defense to help inform and protect organizations.


Your feedback makes our bulletin better! Please tell us what you love and what you would change at ips-news@cisco.com.

Please click here to view a web version of this bulletin.

Visit the Cisco Event Response for more information, analysis, and guidance on this month's Microsoft Security Bulletin Release.


Please click here to download the latest IPS signature update package (sensor only).

Please click here to download the latest Cisco Security Manager (CSM) signature update package.

Download the S669 sensor package (sensor only).

Important Notes

 
7.1(6)E4 Service Pack Release NEW
 
The 7.1(6)E4 service pack reverses the SMB protocol related inspection enhancements delivered as part of 7.1(5)E4 release and also addresses a Signature downgrade issue with SSM platforms.
 
Additionally, as part of this release new features have been added for HTTP Advanced decoding and Signature threat profiles (Signature templates).

This service pack contains the S648 signature level, but preserves any more recent signature levels installed on your sensor.

Cisco IPS 7.1(6)E4 is supported on the following platforms:
 - IPS 4240
 - IPS 4255
 - IPS 4260
 - IPS 4270-20
 - IPS 4345
 - IPS 4345-DC
 - IPS 4360
 - ASA 5500 AIP SSM-10
 - ASA 5500 AIP SSM-20
 - ASA 5500 AIP SSM-40
 - ASA 5512-X IPS SSP
 - ASA 5515-X IPS SSP
 - ASA 5525-X IPS SSP
 - ASA 5545-X IPS SSP
 - ASA 5555-X IPS SSP
 - ASA 5585-X IPS SSP-10
 - ASA 5585-X IPS SSP-20
 - ASA 5585-X IPS SSP-40
 - ASA 5585-X IPS SSP-60

 
For additional details please  see the following link
 
IOS IPS Important Notice - UPDATED

IOS IPS customers running version 12.4T, 15.0M, or 15.1M - a critical software defect has been identified which may cause your router to reload and be stuck in a boot loop if IOS IPS signature version S639 or later is installed on the device. Recovery of impacted devices is possible only via a serial console connection through the device's ROMMON mode. For customers who are using IOS IPS signatures S638 or earlier, there is no issue. Customers wishing to upgrade the IOS IPS signature version to S639 or later must first be running a fixed version of IOS on the device prior to upgrading the IPS signatures.  Fixed versions of IOS include: 15.2(4)M, 15.1(3)T4, 15.2(3)T1, 15.1(4)M5, 12.4(24)T8 and later. Please refer to defect CSCtz27137 for additional details and steps to recover impacted devices. If you need further assistance please contact Cisco TAC

If you have upgraded your version of IOS to 15.2(4)M, 15.1(3)T4, 15.2(3)T1, 15.1(4)M5, 12.4(24)T8 or later you can obtain the most recent signature updates by contacting Cisco TAC.
 
WARNING: CISCO.COM IP ADDRESS CHANGE IN AUTO UPDATE CONFIGURATION

The 7.0(8)E4 service pack changes the default value of Cisco server IP address from 198.133.219.25 to 72.163.4.161 in the Auto Update URL configuration. Firewall rules may need to be updated to allow sensor connectivity to this new IP Address if the Cisco.com Auto Updates have been configured on your sensor.
 
 
Supported Sensor Software Versions

Signature updates are currently tested on the following sensor software releases according to the terms
defined in the End-of-Sale Policy for Signature File Release on Intrusion Detection and Prevention (IDS/IPS) Sensors:

6.0(6) (Released: 29/MAR/2010)

6.2(4) (Released: 27/JUN/2011)
7.0(6) (Released: 13/SEP/2011) (upgrade soon!)
7.0(7) (Released: 31/JAN/2012) (upgrade soon!)
7.0(8) (Released: 29/MAY/2012) (new!)
7.1(3) (Released: 06/DEC/2011) (upgrade soon!)
7.1(4) (Released: 05/MAR/2012) (upgrade soon!)
7.1(5)
(Released: 16/JUL/2012) (upgrade soon!)
7.1(6)
(Released: 04/SEP/2012) (new!)

Please upgrade to one of these sensor software versions to ensure correct sensor operation and effective signature coverage.



Release S669 - September 20, 2012
Release Summary

Vulnerability CVE Severity Risk Rating Signature ID History Status
Adobe Flash Player .mp... CVE-2012-0754 High 90 1373.0 New Enabled
BaoFeng Storm mps.dll... CVE-2009-1612 High 85 1446.0 New Enabled
IBM Tivoli Directory S... CVE-2011-1206 High 90 1450.0 New Enabled
Microsoft Internet Exp... CVE-2011-1260 High 90 37726.1 New Enabled
High 90 37726.2 New Enabled
Microsoft Internet Exp... CVE-2011-2001 High 85 39806.1 New Enabled
Microsoft Report Viewe... CVE-2011-1976 High 90 1396.0 New Enabled
NetSupport Manager Hos... CVE-2011-0404 High 90 41426.0 New Enabled
Novell ZENworks Deskto... High 90 36790.0 New Enabled
RealNetworks RealPlaye... CVE-2010-3747 High 95 39966.0 New Enabled
Symantec pcAnywhere Au... CVE-2011-3478 High 85 41986.0 New Enabled
Adobe Acrobat and Read... CVE-2012-4148 Medium 68 1393.0 New Enabled
RealNetworks RealPlaye... CVE-2010-3747 Component 15 39966.1 New Enabled
Component 15 39966.2 New Enabled
Microsoft SharePoint S... CVE-2011-0653 High 90 39106.0 Updated Enabled
Microsoft Windows win3... CVE-2011-5046 High 90 41806.0 Updated Enabled

SSH Traffic Over Non-s... Info 21 11233.3 Not Retired Retired

+ 27 Retired Signatures
New Vulnerability and Exploit Protections

RealNetworks RealPlayer ActiveX Control Uninitialized Memory Pointer Vulnerability
Vulnerability Disclosed: 3/18/2011, CVSS Base: 9.3, Temporal: 6.9
RealNetworks RealPlayer contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. The vulnerability is due to invalid memory operations performed by the RealPlayer ActiveX control. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to visit a malicious website. If successful, the attacker could execute arbitrary code on the system with the privileges of the user. Functional code that demonstrates an exploit of this vulnerability is publicly available. RealNetworks has confirmed this vulnerability and released updated software.
Severity Description Protected Since Signature ID Default Action
High Realplayer CDDA URI Vulnerability 9/20/2012 39966.0 Block*
Component Realplayer CDDA URI Vulnerability 9/20/2012 39966.1  
Component Realplayer CDDA URI Vulnerability 9/20/2012 39966.2  
More Details:
CVE-2010-3747


Novell ZENworks Desktop Management TFTP Server Component Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 12/14/2010, CVSS Base: 6.8, Temporal: 5.0
Novell ZENworks Desktop Management contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because the Trivial File Transfer Protocol (TFTP) server component that is used by the affected software fails to perform sufficient boundary checks on user-supplied input. An unauthenticated, remote attacker could exploit this vulnerability by submitting crafted packets to the TFTP server component. Processing such requests could result in a memory corruption error that could allow the attacker to execute arbitrary code on the targeted system. Novell has confirmed this vulnerability and released updated software.
Severity Description Protected Since Signature ID Default Action
High Novell ZENworks Desktop Management TFTPD Code Execution 9/20/2012 36790.0 Block*


Microsoft Internet Explorer layout-grid-char Memory Corruption Vulnerability
Vulnerability Disclosed: 6/14/2011, CVSS Base: 9.3, Temporal: 6.9
Microsoft Internet Explorer contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a vulnerable system. The vulnerability is due to errors that may occur when Internet Explorer handles deleted or uninitialized objects. Exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system with the privileges of a targeted user. Functional code that demonstrates an exploit of this vulnerability is publicly available. Microsoft has confirmed this vulnerability in a security bulletin and released updated software.
Severity Description Protected Since Signature ID Default Action
High Microsoft Internet Explorer Memory Corruption Vulnerability 9/20/2012 37726.1 Block*
High Microsoft Internet Explorer Memory Corruption Vulnerability 9/20/2012 37726.2 Block*
More Details:
CVE-2011-1260
Applied Mitigation Bulletin: 23351
CVE-2011-1260
Applied Mitigation Bulletin: 23351
CVE-2011-1260
Applied Mitigation Bulletin: 23351


Microsoft Internet Explorer Virtual Function Table Processing Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 10/11/2011, CVSS Base: 9.3, Temporal: 6.9
Microsoft Internet Explorer versions 6, 7, 8, and 9 contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to improper handling of malformed web pages. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to view a malicious website. If successful, the attacker could execute arbitrary code on the system with the privileges of the user. Microsoft has confirmed this vulnerability in a security bulletin and has released updated software.
Severity Description Protected Since Signature ID Default Action
High Microsoft Internet Explorer Memory Corruption Vulnerability 9/20/2012 39806.1 produce-alert
More Details:
CVE-2011-2001
Applied Mitigation Bulletin: 24318
CVE-2011-2001
Applied Mitigation Bulletin: 24318


NetSupport Manager Hostname Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 11/1/2011, CVSS Base: 10.0, Temporal: 8.1
NetSupport Manager contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code. The vulnerability is due to insufficient sanitization of user-supplied input by the affected software. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious requests to the affected software. If successful, the attacker could execute arbitrary code on the affected system. Proof-of-concept code that exploits this vulnerability is publicly available. NetSupport has not confirmed this vulnerability and updated software is not available.
Severity Description Protected Since Signature ID Default Action
High Netsupport Manager Buffer Overflow 9/20/2012 41426.0 Block*
More Details:
CVE-2011-0404


Symantec pcAnywhere Authentication Information Processing Remote Code Execution Vulnerability
Vulnerability Disclosed: 1/25/2012, CVSS Base: 8.3, Temporal: 6.1
Symantec pcAnywhere contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to improper input data validation during login and authentication procedures in the Symantec pcAnywhere application. An unauthenticated, remote attacker can exploit the vulnerability to run arbitrary code on the system, resulting in unauthorized access to the network and privilege escalation. Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available. Symantec has confirmed the vulnerability and released software updates.
Severity Description Protected Since Signature ID Default Action
High PCAnywhere Pre-authentication Buffer Overflow 9/20/2012 41986.0 produce-alert
More Details:
CVE-2011-3478


Adobe Flash Player .mp4 Media File Buffer Overflow Remote Code Execution Vulnerability
Vulnerability Disclosed: 2/15/2012, CVSS Base: 9.3, Temporal: 7.7
Adobe Flash Player contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code. The vulnerability is due to a memory corruption error while processing an .mp4 media file. An unauthenticated, remote attacker could exploit the vulnerability by convincing a user to visit a malicious web page that hosts crafted .mp4 media files. When processed, the files could cause a memory corruption error that could allow the attacker to execute arbitrary code with the privileges of the user. Exploit code as part of the Metasploit framework is publicly available. Adobe has confirmed the vulnerability and released software updates.
Severity Description Protected Since Signature ID Default Action
High Adobe Flash Player MP4 File Memory Corruption Vulnerability 9/20/2012 1373.0 Block*
More Details:
CVE-2012-0754


Adobe Acrobat and Reader Unspecified Memory Corruption Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 8/16/2012, CVSS Base: 10.0, Temporal: 7.4
Adobe Acrobat and Reader contain a memory corruption vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on a targeted system. The vulnerability is due to an unspecified memory corruption error in the affected software. An unauthenticated, remote attacker could exploit the vulnerability by convincing a user to view a website or open a file that is designed to pass malicious input to the affected software. When processed, the input could cause a memory corruption error in the software. The attacker could use the memory corruption to execute arbitrary code or cause a DoS condition on the system. Adobe has confirmed the vulnerability and released updated software.
Severity Description Protected Since Signature ID Default Action
Medium Adobe Acrobat Denial of Service 9/20/2012 1393.0 produce-alert
More Details:
CVE-2012-4148


Microsoft Report Viewer Controls Cross-Site Scripting Vulnerability
Vulnerability Disclosed: 8/10/2011, CVSS Base: 4.3, Temporal: 3.2
Microsoft Report Viewer contains a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a targeted system. The vulnerability is due to improper validation of data source parameters. An unauthenticated remote attacker could exploit the vulnerability by convincing a user to click a link that is designed to inject script code in the user's browser. If successful, the attacker could spoof content or obtain sensitive information. Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available. Microsoft has confirmed this vulnerability in a security bulletin and has released updated software.
Severity Description Protected Since Signature ID Default Action
High Microsoft Visual Studio Cross Site Scripting (XSS) Vulnerability 9/20/2012 1396.0 Block*
More Details:
CVE-2011-1976
Applied Mitigation Bulletin: 23842


BaoFeng Storm mps.dll ActiveX Control Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 8/10/2010
BaoFeng Storm versions prior to 3.9 contain a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on the targeted system. The vulnerability is due to insufficient sanitization of user input supplied to the nBeforeVideoDownload() method that is implemented in the mps.dll ActiveX control of the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to visit a malicious website designed to pass overly large input to the affected method. The processing of the input could result in a stack-based buffer overflow. The attacker could use this overflow to execute arbitrary code under the security context of the targeted user. Failed exploit attempts could lead to abnormal termination of the browser, causing a DoS condition. Reports suggest that additional arbitrary code execution vulnerabilities also exist in the product. They could exist in Config.dll and CreateChinagames() method in CGAgent.dll ActiveX controls. Exploits are currently being observed in the wild; exploits are most common in China, where the affected product is a frequently used media player. Proof-of-concept code that exploits this vulnerability is publicly available. Administrators are advised to implement an intrusion prevention system (IPS) or intrusion detection system (IDS) to help detect and prevent attacks that attempt to exploit this vulnerability. Administrators may consider setting the kill bit on the following CLSIDs: 6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB, BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05, and 75108B29-202F-493C-86C5-1C182A485C4C. BaoFeng has confirmed this vulnerability and released updated software.
Severity Description Protected Since Signature ID Default Action
High BaoFeng Storm ActiveX Control Buffer Overflow Vulnerability 9/20/2012 1446.0 produce-alert
More Details:
CVE-2009-1612


IBM Tivoli Directory Server ibmslapd.exe Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 4/5/2011, CVSS Base: 9.3, Temporal: 7.5
IBM Tivoli Directory Server contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. The vulnerability exists because the affected software does not perform sufficient boundary checks on user-supplied parameters when handling certain requests. An unauthenticated, remote attacker could exploit this vulnerability by submitting a malformed request to the affected server. If successful, the attacker could execute arbitrary code on the targeted server with the privileges of the affected application. Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available. IBM has confirmed this vulnerability and updates are available.
Severity Description Protected Since Signature ID Default Action
High IBM Tivoli Directory Server ibmslapd.exe Integer Overflow 9/20/2012 1450.0 Block*
More Details:
CVE-2011-1206


Updated Vulnerability and Exploit Protections

Microsoft SharePoint Server Calendar Cross-Site Scripting Vulnerability
Vulnerability Disclosed: 9/13/2011, CVSS Base: 4.3, Temporal: 3.2
Microsoft Office SharePoint Server 2010 SP1 and prior and SharePoint Foundation 2010 contain a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient sanitization of parameters supplied via URL. An unauthenticated, remote attacker could exploit the vulnerability by convincing a user to view a malicious URL. If successful, the attacker could conduct cross-site scripting attacks and possibly access sensitive browser-based information. Microsoft confirmed the vulnerability in a security bulletin and released software updates.
Severity Description Originally Released Signature ID Default Action
High Sharepoint Cross Site Scripting 9/13/2011 39106.0 Block*
More Details:
CVE-2011-0653
Applied Mitigation Bulletin: 24110


Microsoft Windows win32k.sys Kernel Driver Arbitrary Code Execution Vulnerability
Vulnerability Disclosed: 2/14/2012, CVSS Base: 9.3, Temporal: 7.1
Microsoft Windows contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability is due to a buffer overflow error in the affected software while processing user-supplied input parameters. An unauthenticated, remote attacker could exploit the vulnerability by convincing a user to visit a malicious website. If successful, the attacker could execute arbitrary code on the system with kernel privileges. Proof-of-concept code that demonstrates an exploit of this vulnerability is publicly available. Microsoft has confirmed the vulnerability and released software updates.
Severity Description Originally Released Signature ID Default Action
High Windows Kernel-Mode Drivers GDI Access Violation Vulnerability 2/14/2012 41806.0 Block*
More Details:
CVE-2011-5046


Retired Signatures

Signature ID Previous Status Signature Name Threat Name
11233.3 Disabled SSH Over Non-standard Ports SSH Traffic Over Non-standard Ports
40686.0 Retired Iconics Genesis Operation Code 0xDB0 or 0xDBE Integer Overflow ICONICS Genesis Multiple Memory Corruption Vulnerabilities
40707.0 Retired Iconics Genesis Operation Code 0xFA7 Integer Overflow ICONICS Genesis Multiple Memory Corruption Vulnerabilities
40708.0 Retired Iconics Genesis Operation Code 0x1BBC or 0x1BBD Integer Overflow ICONICS Genesis Multiple Memory Corruption Vulnerabilities
40746.0 Retired Iconics Genesis Operation Code 0x1C84 Integer Overflow ICONICS Genesis Multiple Memory Corruption Vulnerabilities
41686.0 New Oracle Outside In CorelDRAW File Parser Integer Overflow Oracle Outside In Technology CorelDRAW File Parser Arbitrary Code Execution Vulnerability
1273.1 New Microsoft Internet Explorer 8 Memory Corruption Vulnerability Microsoft Internet Explorer center Element Processing Arbitrary Code Execution Vulnerability
5442.1 New Cursor and Icon File Format Buffer Overflow Microsoft Windows Cursor and Icon Format Handling Arbitrary Code Execution Vulnerability
1356.0 New Adobe Flash Player URL Security Domain Checking Vulnerability Adobe Flash Player and AIR URL Security Domain Checking Arbitrary Code Execution Vulnerability
34606.0 New Microsoft PowerPoint Memory Corruption Vulnerability Microsoft Office PowerPoint File Memory Corruption Vulnerability
41626.0 New Microsoft Internet Explorer Cloned Object Memory Corruption Vulnerability Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
41626.1 New Microsoft Internet Explorer Cloned Object Memory Corruption Vulnerability Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
41626.2 New Microsoft Internet Explorer Cloned Object Memory Corruption Vulnerability Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
41626.3 New Microsoft Internet Explorer Cloned Object Memory Corruption Vulnerability Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability
1374.0 New Trend Micro ServerProtect EarthAgent RPC Buffer Overflow Vulnerability Trend Micro ServerProtect for Windows and NetWare StRpcSrv.dll RPC Request Buffer Overflow Vulnerability
41967.0 New Apple Safari WebKit Remote Denial of Service Apple Safari Crafted HTML Remote Denial of Service Vulnerability
36406.1 New RealPlayer AVI Processing Arbitrary Code Execution RealNetworks RealPlayer vidplin.dll .AVI Processing Arbitrary Code Execution Vulnerability
35032.0 New SIS Device Buffer Overflow SiS Device Remote Buffer Overflow Vulnerability
35986.0 New PLC HMI Buffer Overflow Multiple Vendor SCADA Systems Programmable Logic Controller Protocol Weaknesses
35027.0 New Invalid MMS ISO Transport Service Packet Manufacturing Messaging Specification ISO Transport Service Packet Processing Denial of Service Vulnerability
39306.0 New Google Chrome No Warning For Malicious Files Google Chrome No Warning for Malicious File Types Issue
41206.0 New Oracle Database Workspace Manager SQL Injection Oracle Critical Patch Update April 2009
41366.0 New Grand Theft Auto San Andreas Multiplayer Server Buffer Overflow Grand Theft Auto San Andreas Multiplayer Server Memory Corruption Vulnerability
39446.0 New 7T IGSS Buffer Overflow 7-Technologies Interactive Graphical SCADA System Multiple Vulnerabilities
39447.0 New 7T IGSS Buffer Overflow 7-Technologies Interactive Graphical SCADA System Multiple Vulnerabilities
39466.0 New 7T IGSS Buffer Overflow 7-Technologies Interactive Graphical SCADA System Multiple Vulnerabilities
39467.0 New 7T IGSS Buffer Overflow 7-Technologies Interactive Graphical SCADA System Multiple Vulnerabilities

* Inline sensor with Event Action Override set to "deny-packet-inline" at Risk Rating 90 (Cisco default configuration)

Sensor Update Information

Signature Updates

Signature updates may be downloaded automatically by Cisco Security Manager (CSM), IPS Manager Express (IME) and Cisco Security Monitoring, Analysis, and Response System (CS-MARS). The following links are for manual downloads.

Sensor Appliance Updates
IPS 4200-series sensors, IPS 4300-series sensors, IDSM2 Catalyst module, AIM-IPS module, ASA-AIP IPS modules

IOS IPS Updates
IOS IPS in Mainline and T-Train Releases prior to 12.4(11)T (Includes NEW Basic and Advanced Set)
IOS IPS in 12.4(11)T or later T-Train

Cisco.com FTP Access Change

Cisco will no longer be distributing software that requires a contract or login credentials via ftp.cisco.com from October 2010. Most IPS users will not be affected unless you have manually configured this to download from ftp.cisco.com.

IPS software and signature updates will continue to be available from Cisco.com. These can be retrieved using the built-in authenticated download capabilities in the IDM, IME, MARS and CSM management and monitoring applications or manually from the Software Download area on Cisco.com. Please see the FAQ for more information on manually downloading updates from the Software Download area.

Please direct any questions or concerns regarding this change to ftp_download_feedback@cisco.com.



New Product Announcements


End of Life and End of Sale Announcements

Security Research Library
Increase your knowledge of today's vulnerabilities, tomorrow's threats, and the technology necessary to keep up.
Cisco Security Intelligence Operations
Comprehensive threat intelligence, analysis, and defense to help inform and protect organizations.
Cyber Risk Reports
Weekly strategic intelligence product that highlights current security activity and mid- to long-range perspectives, also available as a podcast.
Listen
Cisco IntelliShield Alerts
Up-to-the-minute, actionable intelligence, in-depth vulnerability analysis, and highly reliable threat validation to assist in proactive prevention.
Cisco Applied Mitigation Bulletins
Techniques that use Cisco product abilities to detect and mitigate the most important security events and vulnerabilities.
Virus Watch
Current virus trends from SenderBase ©
Spam Watch
Current spam trends from SenderBase ©
Security Multimedia Library
Podcasts, video datasheets, webcasts and videos with solutions for today's problems.
Cisco Security Intelligence Operations Best Practices
Guidance on specific technologies and problem sets to help organizations secure business applications and processes by identifying, preventing, and adapting to threats.
Cisco Security Services
Professional services to support your Self-Defending Network.
Cisco Security Solutions
Discover the breadth of Cisco solutions available to solve your organization's security issues.
Cisco Security Blog
Collaborate with the Cisco Security Community and gain insights into emerging security threats, trends, and best practices.



This document is provided on an "as is" basis and does not imply any kind of guarantee or warranty, including the warranties of merchantability or fitness for a particular use. Your use of the information on the document or materials linked from the document is at your own risk. Cisco reserves the right to change or update this document at any time.

Contacts | Feedback | Subscribe | Unsubscribe
Terms & Conditions | Privacy Statement | Trademarks of Cisco Systems Inc.

© 1992-2012 Cisco Systems Inc. All rights reserved.