Cisco reveals multiple Clean Access flaws

By
Follow google news

Cisco Systems has reported multiple privilege-escalation vulnerabilities affecting the networking giant's Clean Access software solution.


The flaws could be exploited by attackers to "bypass security restrictions or gain knowledge of sensitive information," according to a French Security Incident Response Team (FrSIRT) advisory.

The first flaw is caused by the improper configuration of a secret shared by the Cisco Clean Access Manager (CAM) and Clean Access Server (CAS). The second is caused when manual database backups, or snapshots, stored on the CAM are given predictable filenames.

According to a Cisco advisory, backups taken on CAM are "not encrypted or otherwise protected."

FrIST rated the vulnerabilities "high risk," while Secunia assigned them a "moderately critical" rating.

There are no workarounds, although the Cisco advisory suggests administrators remove "readable snapshot files" soon after they are created.

Both FrIST and Secunia recommend upgrading to the latest versions of Clean Access, which is designed to detect and clean infected endpoint devices attempting to connect to the network.

News of the bugs came as Cisco today announced an US$830 million purchase of email security firm IronPort.

Click here to email reporter Dan Kaplan.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

ASD warns of Australian attacks on N-able N-central RMM

ASD warns of Australian attacks on N-able N-central RMM

NDIA fended off March TeamPCP supply-chain hackers

NDIA fended off March TeamPCP supply-chain hackers

How a Texas student blew the whistle on a rogue AI hacking attempt

How a Texas student blew the whistle on a rogue AI hacking attempt

Researchers chain Tesla charger bug into a four-vendor EV worm

Researchers chain Tesla charger bug into a four-vendor EV worm

Log In

  |  Forgot your password?