Cisco Security Agent Management Center Authentication Bypass Vulnerability
BID:20852
Info
Cisco Security Agent Management Center Authentication Bypass Vulnerability
| Bugtraq ID: | 20852 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2006 12:00AM |
| Updated: | Nov 02 2006 05:02PM |
| Credit: | An unknown third-party reported this issue to the vendor. |
| Vulnerable: |
Cisco Security Agent Management Center 5.1 |
| Not Vulnerable: |
Cisco Security Agent Management Center 5.1 .79 |
Discussion
Cisco Security Agent Management Center Authentication Bypass Vulnerability
Cisco Security Agent Management Center (CSAMC) is prone to an authentication-bypass vulnerability because the application fails to properly handle LDAP error responses.
Exploiting this issue allows remote attackers to gain administrative access to the web-based administrative interface of the affected application.
This issue affects Cisco Security Agent Management Center 5.1 prior to 5.1.0.79.
This issue is being tracked by Cisco Bug ID CSCsg40822.
Cisco Security Agent Management Center (CSAMC) is prone to an authentication-bypass vulnerability because the application fails to properly handle LDAP error responses.
Exploiting this issue allows remote attackers to gain administrative access to the web-based administrative interface of the affected application.
This issue affects Cisco Security Agent Management Center 5.1 prior to 5.1.0.79.
This issue is being tracked by Cisco Bug ID CSCsg40822.
Exploit / POC
Cisco Security Agent Management Center Authentication Bypass Vulnerability
Attackers can use a web client to exploit this issue.
Attackers can use a web client to exploit this issue.
Solution / Fix
Cisco Security Agent Management Center Authentication Bypass Vulnerability
Solution:
Cisco has released an advisory along with fixes to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
Solution:
Cisco has released an advisory along with fixes to address this issue. Please see the referenced advisory for information on obtaining and applying fixes.
References
Cisco Security Agent Management Center Authentication Bypass Vulnerability
References:
References: