Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
BID:14783
Info
Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
| Bugtraq ID: | 14783 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2005 12:00AM |
| Updated: | Sep 08 2005 12:00AM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Cisco CSS11501 Content Services Switch Cisco CSS11500 Content Services Switch |
| Not Vulnerable: | |
Discussion
Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
Cisco CSS (Content Services Switches) 11500 Series devices are prone to an authentication bypass vulnerability. This issue may occur when the device uses SSL for encryption and client authentication.
Successful exploitation may permit unauthorized access to content.
This issue affects Cisco CSS 11500/11501 devices with the CSS5-SSL-K9/CSS11501S-K9 modules installed respectively.
Cisco CSS (Content Services Switches) 11500 Series devices are prone to an authentication bypass vulnerability. This issue may occur when the device uses SSL for encryption and client authentication.
Successful exploitation may permit unauthorized access to content.
This issue affects Cisco CSS 11500/11501 devices with the CSS5-SSL-K9/CSS11501S-K9 modules installed respectively.
Exploit / POC
Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
Solution:
Cisco has released firmware revision 7.40 b119s (sg0740119s.adi) to address the issue on the 7.4 release train. Firmware revision 7.50 b11s (sg0750011s.adi) addresses the issue on the 7.5 release train. Please see the attached Cisco advisory for further information on obtaining and applying fixes.
Solution:
Cisco has released firmware revision 7.40 b119s (sg0740119s.adi) to address the issue on the 7.4 release train. Firmware revision 7.50 b11s (sg0750011s.adi) addresses the issue on the 7.5 release train. Please see the attached Cisco advisory for further information on obtaining and applying fixes.
References
Cisco CSS 11500 Series SSL Authentication Bypass Vulnerability
References:
References: