Cisco Internet Content Distribution Network SSL Vulnerability
A vulnerability exists in Cisco’s Internet Content Distribution Network (iCDN) that can result in authorized access over Secured Sockets Layer (SSL) through cached credentials.
September 20, 2001
Reported September 12, 2001, byCisco Systems.
VERSIONS AFFECTED
Cisco Systems Internet Content Distribution Network (iCDN) 2.0
DESCRIPTION
Avulnerability exists in Cisco’s Internet Content Distribution Network (iCDN)that can result in authorized access over Secured Sockets Layer (SSL) throughcached credentials. If an error occurs during the client/server handshake overthe SSL connection, the server might store the session's ID in the cache ratherthan discarding it. If the same client attempts a second connection, the servercache already contains the session ID and performs the shorter version of theSSL handshake. As a result, the server skips the client authentication phase,and the connection continues as if the client had successfully authenticated.
VENDOR RESPONSE
Ciscohas issued a noticeregarding this vulnerability and recommends that users of version 2.0 upgrade toversion 2.0.1 through normal support channels. Versions of ICDN prior to 2.0 arenot affected because these prior releases don't use the vulnerable RSA BSAFESSL-J library.
CREDIT
Discovered by Cisco Systems.
About the Author
You May Also Like