Cisco Content Service Switch Management Authentication Bypass Vulnerability
BID:2806
Info
Cisco Content Service Switch Management Authentication Bypass Vulnerability
| Bugtraq ID: | 2806 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2001 12:00AM |
| Updated: | May 31 2001 12:00AM |
| Credit: | This vulnerability was announced to Bugtraq in a Cisco Security Advisory on May 31, 2001. |
| Vulnerable: |
Cisco WebNS 4.1 0B17s Cisco WebNS 4.1 0B13s Cisco WebNS 4.0.1 B19s Cisco WebNS 4.0.1 Cisco WebNS 4.0 1B29s Cisco WebNS 4.0 1B23s |
| Not Vulnerable: | |
Discussion
Cisco Content Service Switch Management Authentication Bypass Vulnerability
The Cisco Content Service Switch is an enterprise level web content switch, designed for load balancing and use as a frontend to a redundant web farm. It was previously manufactured by Arrowpoint.
A problem with the switch can make it possible for a user to elevated privileges. Due to insufficent authentication checking, a user can bookmark the URL he or she is redirected to, and access the switch via that URL without authenication.
This makes it possible for a user gain management privileges on a Content Service Switch without authenication, and could lead to denial of service or alteration of sensitive information.
The Cisco Content Service Switch is an enterprise level web content switch, designed for load balancing and use as a frontend to a redundant web farm. It was previously manufactured by Arrowpoint.
A problem with the switch can make it possible for a user to elevated privileges. Due to insufficent authentication checking, a user can bookmark the URL he or she is redirected to, and access the switch via that URL without authenication.
This makes it possible for a user gain management privileges on a Content Service Switch without authenication, and could lead to denial of service or alteration of sensitive information.
Exploit / POC
Cisco Content Service Switch Management Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cisco Content Service Switch Management Authentication Bypass Vulnerability
Solution:
*** Cisco has announced that their previously released update does not fully resolve this issue. This vulnerability will be fixed in versions of WebNS expected to be released in December 2002 or January 2003.
Solution:
*** Cisco has announced that their previously released update does not fully resolve this issue. This vulnerability will be fixed in versions of WebNS expected to be released in December 2002 or January 2003.
References
Cisco Content Service Switch Management Authentication Bypass Vulnerability
References:
References: