Buffer Overflow in Cisco ACS for Windows

Cisco Secure ACS for Windows contains a buffer overflow condition that can permit a Denial of Service (DoS) attack and a root compromise.

ITPro Today

April 22, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedApril 23, 2003, by Cisco Systems



VERSIONSAFFECTED


CiscoSecure ACS 3.1.1, 3.0.3, 2.6.4, and earlier


DESCRIPTION


CiscoSecure ACS for Windows contains a buffer overflow condition that canpermit a Denial of Service (DoS) attack and a root compromise. Theproblem appears to occur during the software's handling of logonsequences.


Ciscorecommends that customers upgrade to repaired versions of CiscoSecure ACS or install Cisco Secure ACS so that either no externalaccess to management interfaces is permitted or access to theinterfaces is restricted. Users who want to restrict access tomanagement interfaces need to block access to ACS on port 2002.


VENDORRESPONSE


Ciscohas released a bulletinand free upgrades, which you can download from the company's Website.


CREDIT

Discovered byNSFocus.



Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like