Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
BID:28807
Info
Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
| Bugtraq ID: | 28807 |
| Class: | Design Error |
| CVE: |
CVE-2008-1155 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2008 12:00AM |
| Updated: | Apr 18 2008 12:28AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Cisco Network Admission Control 4.1 Cisco Network Admission Control 4.0 Cisco Network Admission Control 3.6 Cisco Network Admission Control 3.5 |
| Not Vulnerable: |
Cisco Network Admission Control 4.1.2 Cisco Network Admission Control 4.0.6 Cisco Network Admission Control 3.6.4.4 |
Discussion
Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
Cisco Network Admission Control (NAC) appliance is prone to a remote information-disclosure vulnerability because it fails to securely transmit potentially sensitive data over the network.
Attackers can exploit this issue to harvest the shared secret used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM) to gain unauthorized access to the appliance. This may facilitate the complete compromise of the device and may lead to further attacks. This issue is documented in Cisco Bug ID CSCsj33976.
This issue affects the following versions of the NAC appliance software:
- all 3.5 versions
- all 3.6 versions prior to 3.6.4.4
- all 4.0 versions prior to 4.0.6
- all 4.1 versions prior to 4.1.2
Cisco Network Admission Control (NAC) appliance is prone to a remote information-disclosure vulnerability because it fails to securely transmit potentially sensitive data over the network.
Attackers can exploit this issue to harvest the shared secret used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM) to gain unauthorized access to the appliance. This may facilitate the complete compromise of the device and may lead to further attacks. This issue is documented in Cisco Bug ID CSCsj33976.
This issue affects the following versions of the NAC appliance software:
- all 3.5 versions
- all 3.6 versions prior to 3.6.4.4
- all 4.0 versions prior to 4.0.6
- all 4.1 versions prior to 4.1.2
Exploit / POC
Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
An attacker can exploit this issue by using readily available tools to capture network traffic.
An attacker can exploit this issue by using readily available tools to capture network traffic.
Solution / Fix
Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
Solution:
Cisco has released an advisory and fixes. Please see the references for more information.
Solution:
Cisco has released an advisory and fixes. Please see the references for more information.
References
Cisco Network Admission Control Shared Secret Information Disclosure Vulnerability
References:
References:
- Cisco Homepage (Cisco)
- Network Admission Control Product Page (Cisco)
- Cisco Security Advisory: Cisco Network Admission Control Shared Secret Vulnerabi (Cisco Systems Product Security Incident Response Team
) - Advisory ID: cisco-sa-20080416-nac Cisco Network Admission Control Shared Secret (Cisco)