Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

How to mitigate the impact of the Slammer, Sapphire, and MS SQL worm

Core issue

The worm signature is high volumes of User Datagram Protocol (UDP) traffic to port 1434. Affected customers experience high volumes of traffic from both internal and external systems. Symptoms on Cisco devices include (but are not limited to) high CPU and traffic drops on the input interfaces.

Transmission Control Protocol (TCP) port 1433 and UDP port 1434 are used for Structured Query Language (SQL)server traffic. A new worm targets UDP port 1434. This worm attempts to exploit the buffer overflow vulnerability in Microsoft's SQL Server.

Resolution

For more information, refer to these documents:

582
Views
0
Helpful
0
Comments