Cisco"s CSO talks IOS exploits, open source

24.10.2005
Von Rodney Gedda

A recent spate of vulnerabilities discovered in Cisco"s pervasive Internetwork Operating System (IOS) and the availability of its source code have not detracted from the company"s mission to keep end users informed of security issues, according to CSO John Stewart.

In Australia to brief customers and staff, Stewart defended the increased number of recent advisories for Cisco"s software, saying "We are not just running the network anymore.

"As the company grew there was a correlation between the number of security advisories and the products we offer," he said, adding any assumption that more complexity will lead to more problems is unacceptable.

Why so many specific IOS vulnerabilities? Stewart said this is because Cisco is investing so much money finding vulnerabilities before they are exploited.

"Now that customers don"t want the network to go down, we are spending more dollars to ensure its integrity is upheld," he said.