ADSM-L

Side note on SNMP security alert !

2002-02-28 07:31:25
Subject: Side note on SNMP security alert !
From: "Cook, Dwight E (SAIC)" <cookde AT BP DOT COM>
Date: Thu, 28 Feb 2002 06:27:16 -0600
Slightly off topic but since we are in the recovery position,
anything to help ward off data loss to begin with is close to on topic...
This is all I know for the time being...
Dwight

The Threat
SNMP (Simple Network Management Protocol) is a set of protocols designed for
monitoring and configuring network devices and it operates on every device
connected to the bp network.  We have now been informed of a security bug
that makes the network and all connected devices that use SNMP vulnerable to
attack.  To compound the threat, the techniques for exploiting this
vulnerability were recently published on the internet.   Devices which are
attacked need to be reloaded manually during which time the device would be
unavailable with consequential business disruption.  An exploited widescale
attack would result in a serious denial of service for our network, the
greatest risk being initially to internet connections and internet facing
devices, so we must act now to protect ourselves.    Security patches have
been issued by vendors but it will take some time before these can be
implemented , so we need to act in a way that protects our most vulnerable
devices first.
<Prev in Thread] Current Thread [Next in Thread>