Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Sunday, 21 July 2013

Facebook Open Compute project has "weaknesses," Cisco CEO says

Facebook's Open Compute project, which is working on open source servers and switches, will be limited by "weaknesses" in scope that Cisco can exploit, CEO John Chambers said this week.

In an exclusive interview with Network World where he also touched on the consumer market and EMC alliance, Chambers said efforts like Facebook's to commoditise and wring cost out of hardware purchases will open up opportunities for Cisco to provide solutions that are better tailored to specific customer needs.
"I think this will just be one more series of good challenges that Cisco will say 'what's the business objective on,'" Chambers said of Open Compute. "There are a lot of weaknesses to the area -- we're going to go back and solve customer problems. If you're standalone anything, this is going to be a hard market to play in. Anything white label, where the decision is cost or opex, you're going to lose."
[WHAT CHAMBERS SAID:Cisco building an Internet of Everything router]

What Cisco will not do is sit around and let Open Compute proponents and supporters guide the discussion on commodity switches and servers. Cisco's messaging will be proactive instead of reactive this time.
"What we will not do is leave that concept alone like we did SDN, and allow other people to gain the high ground and then play defense," Chambers said. "This one you will see us out ahead of the game on."
Chambers also addressed Cisco's exit from the consumer market after failures with the Flip videocam and umi TelePresence system, and the recent divestiture of Linksys. Cisco was late addressing opportunities in that market and they ultimately passed the company by.

"Consumer-to-consumer, we're out," Chambers said.  "We missed our window on areas such as Flip and even Linksys. And we made the mistake of getting too fascinated with the device. I love my Flip camera, but it was about FlipShare (video software) in the cloud to any smartphone that would have outmaneuvered Apple. And my team just missed it. Shame on me for not catching it."

Chambers said Cisco is still in the business-to-consumer market through various channels. He said Cisco will not enter markets where it can't gain "sustainable differentiation," 40% share and alignment with its core networking business.

Alignment is also key to the VCE data center coalition Cisco owns with EMC. EMC and its VMware business have been increasingly competitive with Cisco outside of VCE, yet Chambers insists the joint venture is "going to have a good life cycle."

"EMC is a very important strategic partner with us," Chambers said. "VMware is a partner at times, competitor at times."

VMware's entry into networking via the Nicira acquisition strained relations between EMC and Cisco, but turned out to be "the best thing to happen" to the company, Chambers said.
"Even though I wish VMware did not get into networking it was the best thing to happen to us because once they did, then we went back to what we do best:  open architecture, support four hypervisors, not tied to any vendor for strategic long term direction," Chambers said.

Thursday, 27 June 2013

Cisco fixes serious vulnerabilities in email, Web and content security appliances

Cisco Systems released security patches for its email, Web and content security appliances in order to address vulnerabilities that could allow attackers to execute commands on the underlying OS or disrupt critical processes.

 

The vulnerabilities affect different versions of the Cisco IronPort AsyncOS operating system that's used in the Cisco Content Security Management Appliance, the Cisco Email Security Appliance and the Cisco Web Security Appliance.

 

Releases 7.1 and prior, 7.3, 7.5 and 7.6 of the software in the Cisco Email Security Appliance are affected by three vulnerabilities, one that allows remote attackers to inject and execute commands with elevated privileges through the Web interface and two that could be used to crash the management graphical user interface (GUI) or the IronPort Spam Quarantine service and cause other critical processes to become unresponsive.

 

Exploiting the command injection vulnerability requires authentication via the Web interface with at least a low privilege account, but the denial-of-service vulnerabilities can be exploited remotely without authentication.

 

Users of the 7.1 branch should upgrade to version 7.1.5-016 or later, users of the 7.3 branch should upgrade to version 8.0.0-671 and users of the 7.5 and 7.6 branches should upgrade to 7.6.3-019 or later, Cisco said in a security advisory published Wednesday. Releases in the 8.0 branch are not affected.

 

Branches 7.2 and prior, 7.7, 7.8, 7.9 and 8.0 of the Cisco Content Security Management Appliance software are affected by the same command injection and denial-of-service vulnerabilities as the Cisco Email Security Appliance software.

 

All of the vulnerabilities are patched in versions 7.9.1-102 and 8.0.0-404, Cisco said in a separate advisory. Users of 7.2 and prior, 7.7 and 7.8 branches are advised to upgrade to version 7.9.1-102 or later of the software. The 8.1 versions are not affected.

 

Releases 7.1 and prior, 7.5 and 7.7 of the Cisco Web Security Appliance software are vulnerable to two authenticated command injection vulnerabilities and one management GUI denial-of-service vulnerability. Some of the vulnerabilities are the same as those affecting the Cisco Email Security Appliance software.

 

The software releases that include fixes for all three Cisco Email Security Appliance vulnerabilities are 7.5.1-201 and 7.7.0-602. Users of the 7.1 and prior versions are advised to upgrade to 7.5.1-201 or later.

 

Follow me on Twitter @sajilpl