Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
BID:9187
Info
Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
| Bugtraq ID: | 9187 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2003 12:00AM |
| Updated: | Dec 10 2003 12:00AM |
| Credit: | This issue was discovered by Cisco during internal testing. |
| Vulnerable: |
Cisco Content Router 4450 Cisco Content Router 4430 4.1 Cisco Content Router 4430 4.0 Cisco Content Router 4430 Cisco Content Engine Module for Cisco Router 3700 Series Cisco Content Engine Module for Cisco Router 3600 Series Cisco Content Engine Module for Cisco Router 2600 Series Cisco Content Engine 7320 4.1 Cisco Content Engine 7320 4.0 Cisco Content Engine 7320 3.1 Cisco Content Engine 7320 2.2 .0 Cisco Content Engine 7320 Cisco Content Engine 590 4.1 Cisco Content Engine 590 4.0 Cisco Content Engine 590 3.1 Cisco Content Engine 590 2.2 .0 Cisco Content Engine 590 Cisco Content Engine 560 4.1 Cisco Content Engine 560 4.0 Cisco Content Engine 560 3.1 Cisco Content Engine 560 2.2 .0 Cisco Content Engine 560 Cisco Content Engine 507 4.1 Cisco Content Engine 507 4.0 Cisco Content Engine 507 3.1 Cisco Content Engine 507 2.2 .0 Cisco Content Engine 507 Cisco Content Distribution Manager 4670 Cisco Content Distribution Manager 4650 4.1 Cisco Content Distribution Manager 4650 4.0 Cisco Content Distribution Manager 4650 Cisco Content Distribution Manager 4630 4.1 Cisco Content Distribution Manager 4630 4.0 Cisco Content Distribution Manager 4630 Cisco Application & Content Networking Software (ACNS) 5.0.3 Cisco Application & Content Networking Software (ACNS) 5.0.1 Cisco Application & Content Networking Software (ACNS) 5.0 Cisco Application & Content Networking Software (ACNS) 4.2.9 Cisco Application & Content Networking Software (ACNS) 4.2.7 Cisco Application & Content Networking Software (ACNS) 4.2 Cisco Application & Content Networking Software (ACNS) 4.1.3 Cisco Application & Content Networking Software (ACNS) 4.1.1 Cisco Application & Content Networking Software (ACNS) 4.0.3 |
| Not Vulnerable: |
Cisco Application & Content Networking Software (ACNS) 5.1 Cisco Application & Content Networking Software (ACNS) 5.0.5 Cisco Application & Content Networking Software (ACNS) 4.2.11 |
Discussion
Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
Cisco has reported a remotely exploitable buffer overrun in ACNS authentication libraries, which are typically deployed on various Content devices.
The following devices running ACNS software versions prior to 4.2.11 or 5.0.5 are affected:
Content Routers 4400 series
Content Distribution Manager 4600 series
Content Engine 500 and 7300 series
Content Engine Module for Cisco Routers 2600, 3600 and 3700 series
This issue could be potentially exploited to execute arbitrary code on a vulnerable device, resulting in full compromise. Denial of services is another possible consequence of exploitation.
Cisco has reported a remotely exploitable buffer overrun in ACNS authentication libraries, which are typically deployed on various Content devices.
The following devices running ACNS software versions prior to 4.2.11 or 5.0.5 are affected:
Content Routers 4400 series
Content Distribution Manager 4600 series
Content Engine 500 and 7300 series
Content Engine Module for Cisco Routers 2600, 3600 and 3700 series
This issue could be potentially exploited to execute arbitrary code on a vulnerable device, resulting in full compromise. Denial of services is another possible consequence of exploitation.
Exploit / POC
Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
Solution:
This issue has been addressed in the 4.2.11 and 5.0.5 releases of ACNS. The 5.1 releases are also not vulnerable to this issue. Upgrades may be obtained through Cisco's Software Center.
Solution:
This issue has been addressed in the 4.2.11 and 5.0.5 releases of ACNS. The 5.1 releases are also not vulnerable to this issue. Upgrades may be obtained through Cisco's Software Center.
References
Cisco ACNS Authentication Library Remote Buffer Overrun Vulnerability
References:
References: