21/01/2009 Jump security restrictions in Cisco Security Manager 3.x
Cisco has released an update to Cisco Security Manager 3.x fixes a security flaw that could allow an attacker unauthenticated remote could bypass certain security restrictions.
When Cisco Security Manager is used with Cisco IPS Event Viewer (IEV) could open certain TCP ports in the Cisco Security Manager server and IEV client, which could be used by a remote attacker to login as root IEV MySQL database and its server.
Cisco, through the usual channels, has provided its customers with solutions to solve the problem.
Cisco has released an update to Cisco Security Manager 3.x fixes a security flaw that could allow an attacker unauthenticated remote could bypass certain security restrictions.
When Cisco Security Manager is used with Cisco IPS Event Viewer (IEV) could open certain TCP ports in the Cisco Security Manager server and IEV client, which could be used by a remote attacker to login as root IEV MySQL database and its server.
Cisco, through the usual channels, has provided its customers with solutions to solve the problem.
is advised to consult the table of vulnerable versions and countermeasures:
http://www.cisco.com/warp/public/707/cisco-sa-20090121-csm.shtml
More Information:
Cisco Security Advisory: Cisco Security Manager Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090121-csm.shtml
Source: www.hispasec.com
0 comments:
Post a Comment