Cisco IDS Management Software SSL Certificate Validation Vulnerability
BID:14628
Info
Cisco IDS Management Software SSL Certificate Validation Vulnerability
| Bugtraq ID: | 14628 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2005 12:00AM |
| Updated: | Aug 22 2005 12:00AM |
| Credit: | Jan Bervar from NIL Data Communications is credited with the discovery of this issue. |
| Vulnerable: |
Cisco CiscoWorks Monitoring Center for Security 2.1 Cisco CiscoWorks Monitoring Center for Security 2.0 Cisco CiscoWorks Monitoring Center for Security 1.1 Cisco CiscoWorks Management Center for IDS Sensors 2.1 Cisco CiscoWorks Management Center for IDS Sensors 2.0 |
| Not Vulnerable: |
Cisco CiscoWorks Monitoring Center for Security 1.0 Cisco CiscoWorks Management Center for IDS Sensors 1.2 Cisco CiscoWorks Management Center for IDS Sensors 1.1 Cisco CiscoWorks Management Center for IDS Sensors 1.0 |
Discussion
Cisco IDS Management Software SSL Certificate Validation Vulnerability
CiscoWorks Management Center for IDS Sensors, and Cisco Monitoring Center for Security are both susceptible to an SSL certificate validation vulnerability. This issue is due to a failure of the software to properly validate SSL certificates.
Attackers may exploit this vulnerability to spoof SSL certificates, allowing them to impersonate Cisco Intrusion Detection Sensor or Cisco Intrusion Prevention System devices.
By spoofing these connections attackers may gain access to login credentials, aiding them in further attacks. Spoofed connections may also allow for the insertion of false data or the modification or destruction of other valid data contained in the affected management software. This allows attackers to hide the traces of their malicious activity, creating a false sense of security. Other attacks may also be possible.
CiscoWorks Management Center for IDS Sensors, and Cisco Monitoring Center for Security are both susceptible to an SSL certificate validation vulnerability. This issue is due to a failure of the software to properly validate SSL certificates.
Attackers may exploit this vulnerability to spoof SSL certificates, allowing them to impersonate Cisco Intrusion Detection Sensor or Cisco Intrusion Prevention System devices.
By spoofing these connections attackers may gain access to login credentials, aiding them in further attacks. Spoofed connections may also allow for the insertion of false data or the modification or destruction of other valid data contained in the affected management software. This allows attackers to hide the traces of their malicious activity, creating a false sense of security. Other attacks may also be possible.
Exploit / POC
Cisco IDS Management Software SSL Certificate Validation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco IDS Management Software SSL Certificate Validation Vulnerability
Solution:
Cisco has released an advisory and fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
Solution:
Cisco has released an advisory and fixes to address this issue. Please see the referenced advisory for further information on obtaining fixes.
References
Cisco IDS Management Software SSL Certificate Validation Vulnerability
References:
References:
- CiscoWorks Management Center for IPS Sensors Home Page (Cisco)
- CiscoWorks Monitoring Center for Security Home Page (Cisco)
- Cisco Security Advisory: SSL Certificate Validation Vulnerability in IDS Managem (Cisco Systems Product Security Incident Response Team
)