Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
BID:4751
Info
Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
| Bugtraq ID: | 4751 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2002 12:00AM |
| Updated: | May 15 2002 12:00AM |
| Credit: | Vulnerability announced in a Cisco Security Advisory. |
| Vulnerable: |
Cisco Content Router 4430 4.1 Cisco Content Router 4430 4.0 Cisco Content Router 4430 Cisco Content Engine Module for Cisco Router 3700 Series Cisco Content Engine Module for Cisco Router 3600 Series Cisco Content Engine Module for Cisco Router 2600 Series Cisco Content Engine 7325 Cisco Content Engine 7320 4.1 Cisco Content Engine 7320 4.0 Cisco Content Engine 7320 3.1 Cisco Content Engine 7320 2.2 .0 Cisco Content Engine 7320 Cisco Content Engine 590 4.1 Cisco Content Engine 590 4.0 Cisco Content Engine 590 3.1 Cisco Content Engine 590 2.2 .0 Cisco Content Engine 590 Cisco Content Engine 565 Cisco Content Engine 560 4.1 Cisco Content Engine 560 4.0 Cisco Content Engine 560 3.1 Cisco Content Engine 560 2.2 .0 Cisco Content Engine 560 Cisco Content Engine 510 Cisco Content Engine 507 4.1 Cisco Content Engine 507 4.0 Cisco Content Engine 507 3.1 Cisco Content Engine 507 2.2 .0 Cisco Content Engine 507 Cisco Content Distribution Manager 4650 4.1 Cisco Content Distribution Manager 4650 4.0 Cisco Content Distribution Manager 4650 Cisco Content Distribution Manager 4630 4.1 Cisco Content Distribution Manager 4630 4.0 Cisco Content Distribution Manager 4630 Cisco Cache Engine 570 4.0 Cisco Cache Engine 570 3.0 Cisco Cache Engine 570 2.2 .0 Cisco Cache Engine 570 Cisco Cache Engine 550 4.0 Cisco Cache Engine 550 3.0 Cisco Cache Engine 550 2.2 .0 Cisco Cache Engine 550 Cisco Cache Engine 505 4.0 Cisco Cache Engine 505 3.0 Cisco Cache Engine 505 2.2 .0 Cisco Cache Engine 505 |
| Not Vulnerable: | |
Discussion
Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
Cisco Cache Engines offer the ability to proxy HTTP, HTTPS and FTP transactions. Since these services may be placed on one of numerous ports, the default configuration allows a user behind the proxy to connect to another system on any port. Insufficient default access control is set on the device, allowing any user that can connect to the system to proxy a request through to another system.
Cisco Cache Engines offer the ability to proxy HTTP, HTTPS and FTP transactions. Since these services may be placed on one of numerous ports, the default configuration allows a user behind the proxy to connect to another system on any port. Insufficient default access control is set on the device, allowing any user that can connect to the system to proxy a request through to another system.
Exploit / POC
Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
Solution:
Cisco has released fixes to resolve this issue. Affected users may obtain ACNS software versions 4.2, 5.0, or 5.1 depending on support level. See referenced advisory for additional details.
Solution:
Cisco has released fixes to resolve this issue. Affected users may obtain ACNS software versions 4.2, 5.0, or 5.1 depending on support level. See referenced advisory for additional details.
References
Cisco Cache Engine Default Configuration Arbitrary User Proxy Vulnerability
References:
References: