• On TV.com: THE GIRLS NEXT DOOR photos

August 3, 2005 7:36 AM PDT

Cisco warns customers of site breach

  • Print
Cisco Systems' customers received e-mails Wednesday from the networking company advising them of a security breach of its Web site.

The company said Cisco.com has been compromised and that customers need to change their passwords.

"It has been brought to our attention that there is an issue in a Cisco.com search tool that could expose passwords for registered users," the company warned.

"As a result, to protect our registered Cisco.com users, we're taking the proactive step of resetting Cisco.com passwords. Needless to say, we're investigating the incident, which does not appear to be due to a weakness in our security products and technologies or with our network infrastructure."

The company also stressed on its site that the incident appears unrelated to flaws in Cisco products.

Hackers around the world have been racing to find a vulnerability in Cisco equipment since it was described by security researcher Michael Lynn at the Black Hat conference in Las Vegas last week. Cisco and Lynn's former employer, Internet Security Systems, took legal action against the researcher following the presentation.

Cisco said the vulnerability was brought to the company's attention by a third-party security research organization and that no personal customer information had been compromised.

"We would like to thank them for contacting us so we could take appropriate action to protect our customers, partners and employees," a company representative said. "Cisco Systems is investigating the incident, and will work with outside agencies as appropriate."

Regarding the breach, one industry watcher said: "I think this has the possibility of having a significant impact on corporations and the intellectual property of Cisco."

But others disagree. Michael Maddison, director of enterprise risk services at Deloitte Touche Tohmatsu, said that "it's more likely to be a vulnerability in Web applications than Cisco equipment. That's my opinion--we see vulnerabilities in Web pages all the time."

Dan Ilett of Silicon.com reported from London. CNET News.com's Marguerite Reardon contributed to this report.

See more CNET content tagged:
Cisco Systems Inc., incident, vulnerability, password, researcher

Add a Comment (Log in or register) 4 comments
Ain't that a kick in the butt.
by System Tyrant August 3, 2005 9:50 AM PDT
After having security experts tell the world that Cisco routers aren't safe they get hacked. I'm guessing it probably happened because of the C&D order.
Reply to this comment
Get the facts first...
by jasonemanuelson1 August 3, 2005 10:27 AM PDT
The Cisco flaw in question relates to equipment using an old
version of the IOS software, not current versions. Upgrading the
IOS in routers is not really that hard, although many are
reluctant to change what is already working for them, and thus
the reason for the issues in the first place. The website issues
are just that, website issues. That is pretty easy to see, if you are
a Cisco customer or know Cisco's system.

People are undoubtedly anxious about these issues, but just
because they happen at near times does not justify lumping the
together, unless they were related.
View reply
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Cisco Systems (4.84%) 0.70 15.17
Dow Jones Industrials (6.54%) 494.13 8,046.42
S&P 500 (6.32%) 47.59 800.03
NASDAQ (5.18%) 68.23 1,384.35
CNET TECH (5.95%) 56.25 1,002.00
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right