BUT...are obsolete products necessarily tested for all new vulnerabilities?
I'm thinking it's quite possible for an obsolete device to not be shown
as vulnerable even if it is.
Charles
On Mon, Mar 18, 2013 at 10:35 AM, Pete Helgren <pete@xxxxxxxxxx> wrote:
The fact that it is obsolete shouldn't render it vulnerable. A quick
search on vulnerabilities on the device show nothing of import
recently. If it was current on patches when it became obsolete, then it
should be OK. If you hang on to it, then a quick search every couple of
weeks should keep you covered. Also, subscribing to a list of known
vulnerabilities would be a good idea. The SANS institute has several.
Searching the metasploit site would also uncover an exploit should one
surface for the device.
Pete Helgren
www.petesworkshop.com
GIAC Secure Software Programmer-Java
On 3/18/2013 6:59 AM, rob@xxxxxxxxx wrote:
We get regular reports of our internal, and our external, network from
Qualys. Also some benevolent hacking is done. Areas of concern are
ranked in layers of severity with 5 being the area of highest concern and
1 being the area of lowest concern. The one issue we have at a level 5
is
only because the software is obsolete and is no longer issued updates.
<snip>
THREAT:
The Cisco VPN 3000 Series provides remote access deployments for IP
Security (IPsec) and Secure Sockets Layer (SSL) VPN connectivity.
Technical support ended on 31st August 2012. Support services for
the
product are unavailable, and the product is obsolete.
IMPACT:
The system is at high risk of being exposed to security
vulnerabilities. Since the vendor no longer provides updates, obsolete
software is more vulnerable to attacks.
SOLUTION:
Cisco recommends migrating to the Cisco ASA 5500 Series SSL/IPsec
VPN
Edition. Information about this product can be found at Cisco ASA.
COMPLIANCE:
Not Applicable
EXPLOITABILITY:
There is no exploitability information for this vulnerability.
ASSOCIATED MALWARE:
There is no malware information for this vulnerability.
RESULTS:
OS obtained: Cisco VPN 3000 Concentrator
</snip>
This has been on the report for awhile so apparently my boss doesn't
think
it's really all that great a priority. Or perhaps it's asking for budget
money the same quarter that manufacturing tries to load up is unlucky.
Would you or your boss?
Would you or your boss have a concern if that was about some level of IBM
i that you were running that is now obsolete (or will be in a few
months)?
Rob Berendt
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/midrange-l.