GCED · Question #16
Why would a Cisco network device with the latest updates and patches have the service config setting enabled, making the device vulnerable to the TFTP Server Attack?
The correct answer is B. This setting is enabled by default in the current Cisco IOS. Enabling the service config setting causes a Cisco router to be vulnerable to the TFTP Server Attack since it will actively try to retrieve a new configuration file from the nearest TFTP server. An attacker can insert a malicious update file in this process to compromise the…
Question
Why would a Cisco network device with the latest updates and patches have the service config setting enabled, making the device vulnerable to the TFTP Server Attack?
Options
- ADisabling telnet enables the setting on the network device.
- BThis setting is enabled by default in the current Cisco IOS.
- CAllowing remote administration using SSH under the Cisco IOS also enables the setting.
- DAn attack by Cisco Global Exploiter will automatically enable the setting.
- EThis older default IOS setting was inherited from an older configuration despite the upgrade.
How the community answered
(65 responses)- A5% (3)
- B82% (53)
- C3% (2)
- D2% (1)
- E9% (6)
Explanation
Enabling the service config setting causes a Cisco router to be vulnerable to the TFTP Server Attack since it will actively try to retrieve a new configuration file from the nearest TFTP server. An attacker can insert a malicious update file in this process to compromise the Cisco router. The service config setting was disabled by default in the Cisco IOS in version 12.0, but had been enabled by default in the 11.x series of the IOS trains. This feature is often enabled in later versions since organizations don't always realize the risk of this setting and will leave it enabled as the migrate through multiple IOS upgrades. The other items listed don't enable the service config setting.
Topics
Community Discussion
No community discussion yet for this question.