Advertisement
Promo

Industry watch Toolkit

Cisco flaw affects Windows servers

Patrick Gray ZDNet Australia

Published: 24 Apr 2003 08:21 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A potentially critical vulnerability has been found in Cisco Systems' Secure Access Control Server (ACS) for Windows servers, which is used to control devices such as routers in large networks.

The buffer overflow glitch may allow an attacker to seize control of the Cisco service, when running on Windows. The Unix variant is not affected.

Exploitation of the flaw could result in a malicious hacker gaining full control of a target company's security infrastructure, leaving them completely exposed, should they be using ACS to control it.

The ACS system is used to control routers, firewalls, VPNs, VoIP systems, wireless networks, as well as to provision access policies to users.

"Exploitation of this vulnerability results in a denial of service, and can potentially result in system administrator access. Cisco is providing repaired software, and customers are recommended to install patches or upgrade at their earliest opportunity," Cisco said in an advisory released on Wednesday. The advisory contains patches for fixing the bug.

An exploit for the vulnerability is not known to be circulating, and ACS servers are usually deployed on network segments with limited physical access.

The flaw was found by researchers at China-based NSFOCUS. The group is yet to release an advisory of its own.

Administrators of ACS systems can block TCP port 2002 until they can deploy Cisco's fix.

"Customers with contracts should obtain upgraded software through their regular update channels. For most customers, this means that upgrades should be obtained through the Software Center on Cisco's worldwide Web site," the advisory states.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
40 out of 73 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Discussions

juicecultus juicecultus

The link provided is not working

Sunday 6 December 2009, 5:13 PM

1 comment
lezlow lezlow

when it comes with power supply you,ll...

Saturday 5 December 2009, 9:42 PM

3 comments
lezlow lezlow

yer

Saturday 5 December 2009, 9:40 PM

1 comment
lezlow lezlow

HP workers set dates for strikes

Saturday 5 December 2009, 9:39 PM

2 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters