SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Cisco Secure ACS Weak Session Management Vulnerability


Arrow  SecurityAlert : 1157
Arrow  CVE : CVE-2006-3226
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : Darren Bounds
Arrow  Published : 29.06.2006

Arrow  Affected Software : Cisco Secure AC



Arrow  Advisory Content :  

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello -

The Cisco PSIRT has posted a public response to a vulnerability made
public by a researcher on multiple public mailing lists.

This is the Cisco PSIRT response to the statements made by Darren
Bounds in his advisory: Cisco Secure ACS Weak Session Management
Vulnerability. The original email/advisory is available at
http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0618.html
and
http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047301.html

This issue is being tracked by Cisco Bug IDs CSCse26754 and
CSCse26719.

The attacks described in the report take advantage of a weakness in
the default configuration of the Cisco ACS. Cisco is investigating
this issue and further detail will be added to the Cisco Security
Response as it becomes available.

Cisco's statement and further information are available on the Cisco
public website at

http://www.cisco.com/warp/public/707/cisco-sr-20060623-acs.shtml

Contact psirt (at) cisco (dot) com [email concealed] with any questions
regarding this issue.

Regards,

Clay

On Fri, Jun 23, 2006 at 09:18:51AM -0400, Darren Bounds wrote:
> Cisco Secure ACS Weak Session Management Vulnerability
> June 23, 2006
>
> Product Overview:
> Cisco Secure Access Control Server (ACS) provides a centralized
> identity networking solution and simplified user management experience
> across all Cisco devices and security management applications.
>
> Cisco Secure ACS is a major component of Cisco trust and identity
> networking security solutions. It extends access security by combining
> authentication, user and administrator access, and policy control from
> a centralized identity networking framework, thereby allowing greater
> flexibility and mobility, increased security, and user productivity
> gains.
>
> Vulnerability Details:
> A vulnerability has been identified in the Cisco Secure ACS session
> management architecture which could be exploited by an attacker to
> obtain full administrative access to the web interface and thus all
> managed assets (routers, switches, 802.1x authenticated networks,
> etc).
>
> By default, the Cisco Secure ACS web administration login page runs on
> TCP port 2002. Upon successful authentication, the client is then
> redirected to a dynamicand unique HTTP server port between 1024 and
> 65535. Once authenticated, ACS relies solely upon the port and the
> client IP address to validate the session.
>
> Clearly one can think of many somewhat trivial techniques for
> acquiring the necessary IP address or senarios where the attacker may
> already share the same source IP as the administrator (proxies, NATing
> devices). Now it's merely a matter of identifying the port allocated
> for the administrative interface. This is easily accomplished as ACS
> follows a simple incrementation process for port allocation.
>
> Affected Versions:
> Cisco Secure ACS 4.x for Windows
> Legacy versions may also be affected.
>
> Workarounds:
> Configure ACLs within Cisco Secure ACS to restrict access to the web
> interface from only 'secure' network address space.
>
> Cisco has confirmed this vulnerability and is working on a patch.
>
> References:
> http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html
>
>
> --
>
> Thank you,
> Darren Bounds
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (SunOS)

iD8DBQFEnH0XEHa/Ybuq8nARAmrJAJ9RVE0zwyiEGuhU4a8wVTiyEAt0pwCeK2QW
psiCcxc105IojaZsm+i+yjY=
=thsN
-----END PGP SIGNATURE-----





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.