Cisco Reviews Code After Juniper Breach; More Scrutiny Expected

Advertisement
By Reuters | Updated: 22 December 2015 11:32 IST
Networking equipment maker Cisco Systems Inc said on Monday it has launched a product review to look for tampering after rival Juniper Networks Inc's disclosure it found code in firewall software that made in vulnerable to cyber attacks.

Juniper warned customers on Thursday that it had uncovered "unauthorised code" in its firewall software, saying it could be exploited to allow an attacker to unscramble encrypted communications that travel through the security devices.

That prompted the code review by Cisco. Security experts said they expect other technology companies to conduct similar investigations after last week's unprecedented news from Juniper.

Advertisement

It was the first time a major technology firm discovered the addition of an unauthorised 'back door," or code that could be exploited to facilitate cyber attacks, according to security experts.

"I can't imagine there is a major vendor that isn't doing a major code audit now," said HD Moore, chief research officer with Rapid7 Inc .

Advertisement

Technology companies regularly audit their code for bugs, including "back doors" that attackers could leverage to launch cyber attacks on customer networks.

But Moore said that such reviews focus on "back doors" that are unintentionally created, not ones inserted without the manufacturer's knowledge.

Advertisement

"The challenge is that nobody has been looking for this in the past," said Moore, an expert in software vulnerabilities. "If you know you are looking for a malicious backdoor, you have a much better chance of finding something."

Cryptologist Bruce Schneier said that technology companies should have long been looking for unauthorised code, but that many ignored the problem since the reviews boost expenses.

Advertisement

"The fundamental problem is that the market doesn't reward the things we want like secure code. Nobody wants to pay for it," he said.

Cisco said on its blog that the testing will include code reviews by engineers with deep networking and cryptography experience as well as penetration testing, a process where technicians attempt to attack products to find bugs the way malicious hackers might seek to exploit them.

Meanwhile, the US Department of Homeland Security said it was investigating how the Juniper "back door" might impact government networks.

"As we routinely do when such vulnerabilities are brought to light, we are assessing the potential impact, if any, on federal networks, and will take any appropriate mitigation measures in close coordination with interagency partners," said agency spokesman S.Y. Lee.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Cisco, Internet, Juniper
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 18 Pro Max Tipped to Sport a Large Display and This Snapdragon Chip
  2. Dell 15 Refreshed With Up to Intel Core Ultra 7, 15.6-Inch Display
  3. OnePlus Nord CE 6, Nord CE 6 Lite Will Launch in India on This Date
  4. Huawei Pura X Max With 5,300mAh Battery Launched at This Price
  5. Huawei Pura 90 Series Launches in China With These Specifications
  6. Poco C81, C81x to Launch in India With Up to 6,300mAh Battery on This Date
  7. OnePlus Ace 6 Ultra, New Gaming Controller Will Launch on This Date
  8. Oppo Find X9s Spotted on Geekbench With This MediaTek Dimensity SoC
  1. Motorola Razr 2026, Razr+ 2026 Launch Date, Price, Specifications Leaked
  2. Huawei Watch Buds 2 Launched With Built-in Earbuds, LTPO Display: Price, Features
  3. Adobe Introduces CX Enterprise, an Agentic AI Platform to Automate Customer Experience for Businesses
  4. Infinix GT 50 Pro Global Launch Date Announced; Will Debut With Liquid Cooling, Pressure-Sensitive Triggers
  5. Huawei Watch Fit 5, Watch Fit 5 Pro Launched With AMOLED Screens, HarmonyOS and Up to 10 Days Battery Life
  6. Apple Withholds Data in India Antitrust Case, CCI Sets Final Hearing
  7. Anthropic Introduces Claude Design, an AI Tool to Generate Visual Prototypes and Pitch Decks
  8. Nee Forever OTT Release Date: When and Where to Watch This Tamil Romantic Drama Online?
  9. Huawei Pura 90 Pro Max Launched With 200-Megapixel Telephoto Camera Alongside Huawei Pura 90, Pura 90 Pro
  10. Nukkad Naatak OTT Release Date: When and Where to Watch This Social Drama Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.