On 07/01/2014 22:54, Chris Marget wrote:
> FWIW, it seems that the security fixes might be available for free, so long
> as Cisco PSIRT recognizes a vulnerability in a particular bit of software.
> ...But the document describing that process suggests calling TAC, which
> doesn't usually go well if the serial number of the device isn't covered by
> a support contract...
> http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html

This works and I've done it.  There are two main limitations: first, the
caller needs to be the registered owner of the device.  Second, the fix
will usually be from the same or nearest train for the box.  No support
contract is needed.

Nick


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to