Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

BID:9187

Info

Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

Bugtraq ID: 9187
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Dec 10 2003 12:00AM
Updated: Dec 10 2003 12:00AM
Credit: This issue was discovered by Cisco during internal testing.
Vulnerable: Cisco Content Router 4450
Cisco Content Router 4430 4.1
Cisco Content Router 4430 4.0
Cisco Content Router 4430
Cisco Content Engine Module for Cisco Router 3700 Series
Cisco Content Engine Module for Cisco Router 3600 Series
Cisco Content Engine Module for Cisco Router 2600 Series
Cisco Content Engine 7320 4.1
Cisco Content Engine 7320 4.0
Cisco Content Engine 7320 3.1
Cisco Content Engine 7320 2.2 .0
Cisco Content Engine 7320
Cisco Content Engine 590 4.1
Cisco Content Engine 590 4.0
Cisco Content Engine 590 3.1
Cisco Content Engine 590 2.2 .0
Cisco Content Engine 590
Cisco Content Engine 560 4.1
Cisco Content Engine 560 4.0
Cisco Content Engine 560 3.1
Cisco Content Engine 560 2.2 .0
Cisco Content Engine 560
Cisco Content Engine 507 4.1
Cisco Content Engine 507 4.0
Cisco Content Engine 507 3.1
Cisco Content Engine 507 2.2 .0
Cisco Content Engine 507
Cisco Content Distribution Manager 4670
Cisco Content Distribution Manager 4650 4.1
Cisco Content Distribution Manager 4650 4.0
Cisco Content Distribution Manager 4650
Cisco Content Distribution Manager 4630 4.1
Cisco Content Distribution Manager 4630 4.0
Cisco Content Distribution Manager 4630
Cisco Application & Content Networking Software (ACNS) 5.0.3
Cisco Application & Content Networking Software (ACNS) 5.0.1
Cisco Application & Content Networking Software (ACNS) 5.0
Cisco Application & Content Networking Software (ACNS) 4.2.9
Cisco Application & Content Networking Software (ACNS) 4.2.7
Cisco Application & Content Networking Software (ACNS) 4.2
Cisco Application & Content Networking Software (ACNS) 4.1.3
Cisco Application & Content Networking Software (ACNS) 4.1.1
Cisco Application & Content Networking Software (ACNS) 4.0.3
Not Vulnerable: Cisco Application & Content Networking Software (ACNS) 5.1
Cisco Application & Content Networking Software (ACNS) 5.0.5
Cisco Application & Content Networking Software (ACNS) 4.2.11

Discussion

Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

Cisco has reported a remotely exploitable buffer overrun in ACNS authentication libraries, which are typically deployed on various Content devices.

The following devices running ACNS software versions prior to 4.2.11 or 5.0.5 are affected:
Content Routers 4400 series
Content Distribution Manager 4600 series
Content Engine 500 and 7300 series
Content Engine Module for Cisco Routers 2600, 3600 and 3700 series

This issue could be potentially exploited to execute arbitrary code on a vulnerable device, resulting in full compromise. Denial of services is another possible consequence of exploitation.

Exploit / POC

Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

Solution:
This issue has been addressed in the 4.2.11 and 5.0.5 releases of ACNS. The 5.1 releases are also not vulnerable to this issue. Upgrades may be obtained through Cisco's Software Center.

References

Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report