Cisco Secure ACS Insecure Password Storage Vulnerability
BID:16743
Info
Cisco Secure ACS Insecure Password Storage Vulnerability
| Bugtraq ID: | 16743 |
| Class: | Design Error |
| CVE: |
CVE-2006-0561 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 08 2006 12:00AM |
| Updated: | May 15 2006 07:54PM |
| Credit: | Andreas Junestam is credited with the discovery of this issue. |
| Vulnerable: |
Cisco Secure ACS for Windows Server 3.2 Cisco Secure ACS for Windows NT 3.3 Cisco Secure ACS for Windows NT 3.2 Cisco Secure ACS for Windows NT 3.1.1 Cisco Secure ACS for Windows NT 3.1 Cisco Secure ACS for Windows NT 3.0.3 Cisco Secure ACS for Windows NT 3.0 .1 Cisco Secure ACS for Windows NT 3.0 Cisco Secure Access Control Server 3.3.2 Cisco Secure Access Control Server 3.3.1 Cisco Secure Access Control Server 3.3 (1) Cisco Secure Access Control Server 3.3 Cisco Secure Access Control Server 3.2.2 Cisco Secure Access Control Server 3.2.1 Cisco Secure Access Control Server 3.2 (3) Cisco Secure Access Control Server 3.2 (2) Cisco Secure Access Control Server 3.2 (1.20) Cisco Secure Access Control Server 3.2 (1) Cisco Secure Access Control Server 3.2 Cisco Secure Access Control Server 3.1 Cisco Secure Access Control Server 3.0 Cisco Secure Access Control Server |
| Not Vulnerable: |
Cisco Secure ACS Solution Engine Cisco Secure Access Control Server 4.0.1 |
Discussion
Cisco Secure ACS Insecure Password Storage Vulnerability
Cisco Secure ACS is susceptible to an insecure password-storage vulnerability. This issue is due to a failure of the application to properly secure sensitive password information.
This issue allows attackers to gain access to encrypted passwords and to the key used to encrypt them. This allows them to obtain the plaintext passwords, aiding them in attacking other services that depend on the ACS server for authentication.
Cisco Secure Access Control Server for Windows versions 3.x are affected by this issue.
Cisco Secure ACS is susceptible to an insecure password-storage vulnerability. This issue is due to a failure of the application to properly secure sensitive password information.
This issue allows attackers to gain access to encrypted passwords and to the key used to encrypt them. This allows them to obtain the plaintext passwords, aiding them in attacking other services that depend on the ACS server for authentication.
Cisco Secure Access Control Server for Windows versions 3.x are affected by this issue.
Exploit / POC
Cisco Secure ACS Insecure Password Storage Vulnerability
Attackers must use or create an exploit application that is capable of decrypting the encrypted passwords.
The specific means of gaining access to the registry information may or may not require an exploit application.
Attackers must use or create an exploit application that is capable of decrypting the encrypted passwords.
The specific means of gaining access to the registry information may or may not require an exploit application.
Solution / Fix
Cisco Secure ACS Insecure Password Storage Vulnerability
Solution:
ACS 3.x for UNIX and ACS 4.0.1 for Windows are not affected this issue.
Solution:
ACS 3.x for UNIX and ACS 4.0.1 for Windows are not affected this issue.
References
Cisco Secure ACS Insecure Password Storage Vulnerability
References:
References:
- Cisco Secure Access Control Server for Windows (Cisco)
- Re: SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator Password Disclo (Matthew Cerha
) - RE: SYMSA-2006-003: Cisco Secure ACS for Windows - AdministratorPassword Disclos ("John Stuppi (jstuppi)"
) - SYMSA-2006-003: Cisco Secure ACS for Windows - Administrator ([email protected])