Breaking News:

Cisco NAC vulnerable to attack

Cisco Systems has issued an advisory about two serious software vulnerabilities in one of its network access control products, Cisco NAC Appliance, also known as Cisco Clean Access (CCA).

Cisco NAC Appliance, which checks that external devices attempting to log on to a company network are compliant with security policy, contains two flaws that an attacker could use to gain control of the devices, or compromise sensitive information including passwords.

The NAC Appliance includes software that can automatically detect, isolate, and clean infected or vulnerable devices that attempt to access a network. Clean Access consists of two applications that work in tandem -- Clean Access Manager (CAM) and Clean Access Server (CAS).

For the CAM to authenticate to the CAS, each holds a "shared secret" -- pieces of information which, when combined, allow authentication to occur. It appears, though, that this system is flawed in older versions of the software.

According to the Cisco advisory, the vulnerability -- called "unchangeable shared secret" -- means the shared secret cannot be properly set or changed during setup. This also means that the shared secret will be the same across all affected devices, which drastically reduces its cryptographic effectiveness.

To exploit this vulnerability the adversary must first be able to establish a TCP connection to the CAS.

Successful exploitation of the unchangeable shared secret vulnerability may enable a malicious user to take administrative control of a CAS. After that, every aspect of CAS can be changed including its configuration and setup, said Cisco.

Versions affected by this vulnerability are CCA releases 3.6.x to 3.6.4.2 and releases 4.0.x to 4.0.3.2.

Releases that contain the fix for this vulnerability are 3.6.4.3, 4.0.4 and 4.1.0. All subsequent releases already contain a fix.

An alternative is to install patch Patch-CSCsg24153.tar.gz which is available from Cisco's Web site.

The second vulnerability, called "readable snapshots", means that manual backups of the database -- or "snapshots" -- taken on the CAM are susceptible to brute force download attacks. A malicious user can guess the file name and download it without authentication. The file itself is not encrypted or otherwise protected.

The snapshot contains sensitive information that can aid in attacks on the CAS, or can be used to compromise the CAM. Among other things, the snapshot can contain passwords in cleartext.

Versions affected by the readable snapshots vulnerabiltiy are CCA releases 3.5.x to 3.5.9 and releases 3.6.x to 3.6.1.1.

Releases that contain the fix for this vulnerability are 3.5.10 and 3.6.2. All subsequent releases will contain the fix, said Cisco.

No patch is available for the readable snapshots vulnerability, but a workaround is possible by removing snapshot files from the device shortly after they are created. If the snapshot file needs to be preserved then it can be moved to a different computer or archived on a secondary storage, said Cisco. Alternatively, the snapshot file can be deleted from the device.

There are currently no known exploits for either vulnerability. The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities.

The readable snapshot issue was reported to Cisco by Chris Hartley from Ohio State University. The unchangeable shared secret was discovered while working on a Cisco customer's case and is unrelated to Hartley's report, according to Cisco.

Tom Espiner reported for ZDNet UK from London

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

by http://t.co/vmlLt4bh: SA Health's journey to e-health: Implementing e-health services for an entire state is a... http://t.co/NVrBd9c5

Facebook investor to sue Nasdaq over alleged bungled orders: http://t.co/XGRsNzA4 ^LH

Combining @Ariba's network & @SAP's applications - "SAP eyes cloud super network with Ariba buy" http://t.co/jeMWEKpB

SA Health's journey to e-health: Implementing e-health services for an entire state is a daunting task, but, as ... http://t.co/Vwchau6N

RT @JamesVickery: Google warns users of DNSChanger malware http://t.co/DsHUnC5r

Upskill. RT @zdnetaustralia Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/PrFEBfqS ^ST

Google warns users of DNSChanger malware http://t.co/DsHUnC5r

National Botnet Network coming: Earthwave http://t.co/t49r3IV0

Surely IT is more than just a game? http://t.co/WvSk0C0N

RT @JLLLOW: Revolution. RT @zdnetaustralia: Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/rdjqdACC

Revolution. RT @zdnetaustralia: Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/rdjqdACC

Google has joined in on the chorus of organisations warning users about DNSChanger infections http://t.co/ysaIHiuG ^ML

Akku Asus A32-K72 Original,Kompatibler Ersatz akku für Li-ion Asus A32-K72 Original Laptop Akkus Asus A32-K72 Original,A32-K72 Original...

4 hours ago by akkuakku on HP Compaq 6730b

It is great to see the NSW government taking this step, however there's plenty of home-grown talent loeaving or being rediverted due to l...

4 hours ago by Aceyducey on NSW Govt appoints Silicon Valley champion

Job vacancies are down 22 per cent on a year ago. So what are IT professionals to do? http://t.co/EpY9YiFg ^ST

by http://t.co/vmlLt4bh: JobWatch: where the jobs are: The latest analysis on online job ads from the Department ... http://t.co/nh1wg7Y6

@chieftech @zdnetaustralia that's a fair call. Still an area that requires consideration work. BYOD = BYOViruses & Malware :)

JobWatch: where the jobs are http://t.co/Lqo8BNVT

EMC hones focus on hybrid cloud big data Hardware News ZDNet Australia: EMC has launched 42 prod... http://t.co/uR56HXDz #bigdata #blogs

Are specific gaming development degrees bollocks? http://t.co/z2zbaWvT ^ST

#NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/GPrIXH4F via @johnW3LLS #govcamp

JobWatch: where the jobs are: The latest analysis on online job ads from the Department of Education, Employment... http://t.co/qJce42h2

RT @johnW3LLS: #NSW Govt announces shopfront in Silicon Valley + 7 consortia to dev #mobile for public sector http://t.co/JDSdSxWu #gov2au

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

What Microsoft won't tell you about Windows 7 licensing http://t.co/Y2e6sXdI #Win7

#Android fragmentation steers Vic Health - @ZDNet Australia : http://t.co/chrmWl7B

RT @zdnetaustralia: Android fragmentation threw a spanner into Victorian Health's app strategy: http://t.co/4pkmnkMB ^LH

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic Healt... http://t.co/VTbMBy5A #android #news

by http://t.co/vmlLt4bh: Android fragmentation steers Vic Health: Fragmentation issues in Android were a key conc... http://t.co/wOmHdAav

Android fragmentation steers Vic Health http://t.co/CqTImM5l

Android fragmentation steers Vic Health - ZDNet Australia: Android fragmentation steers Vic... http://t.co/3ssDp1SW http://t.co/KpTZdvuO

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/NnjPEqSu

Android fragmentation steers Vic Health http://t.co/jcB7UGer

Chrome beats Internet Explorer in global Web browser race | ZDNet http://t.co/7G7xMfJj

Android fragmentation steers Vic Health: Fragmentation issues in Android were a key concern for the Victorian De... http://t.co/HLdurfS5

Mining the social data stream for deeper customer insight | via @ZDNet http://t.co/x4xouPQh)

Android fragmentation steers Vic Health http://t.co/A6SJkfJw

But this is the thing. There are still plenty of good-quality graduates whose skills can raise seasoned professional eyebrows... if they ...

6 hours ago by techkid on Skills shortage: companies being too picky?

I wouldn't have called Vista cheesy. Its GUI was pretty slick (and indeed handed on to Windows 7). It was, however, poorly implemented, h...

6 hours ago by techkid on Microsoft admits Vista was 'cheesy'

Thanks Nelson, it should be right now.

-Michael.

6 hours ago by Mukimu on Ausgrid network to talk back to operators

I guess the mouse was a necessary evil at the time. I mean, yes, keyboard shortcuts in the right hands are faster than any mouse action (...

6 hours ago by techkid on Microsoft admits Vista was 'cheesy'

fyi google may always lie

7 hours ago by rt luvs youh on Google shows we're killing our language

they probaly always lie about in4mation bout people

7 hours ago by rt luvs youh on Google shows we're killing our language

$6.7million, now we know the price to the tax payer of a government IT project clean up. You've got to ask the question don't you: why o...

8 hours ago by Takenforgranted on Vic scraps HealthSMART system

why some mp4 files with higher frame width can not be played in my 3m mp180??

8 hours ago by cyrusmann_ymail.com on 3M MP180 Pocket Projector

Unfortunately there is NO such place as Nelson's Bay. It's Nelson Bay!! Probably not your fault for the error, as your Media Release prob...

8 hours ago by Nelson on Ausgrid network to talk back to operators

@Wow - thats one of the benefits of the iPad (and tablets in general). They are one of the most generation neutral products ever made. ...

10 hours ago by Gav on Westpac board goes paperless with iPads

and why is this such a super idea? http://www.itnews.com.au/News/301778,thousands-affected-in-billing-cloud-breach.aspx oh, yeah, right...

10 hours ago by btone on Fed Govt steps up on shared cloud plan

Wow, seems like a fantastic initiative that helps to save the environment. It must have taken a lot of convincing to get the Board to mov...

11 hours ago by Wow on Westpac board goes paperless with iPads

I'm a payed up lib member who has voted Labor in the last 2 federal elections. I had the previlege of speaking to Mr Turnball 3 months ag...

11 hours ago by spazmanaught on NBN contracts may be left alone: Turnbull

Good to see Westpac's concentrating on the real IT issues !

11 hours ago by jeff_syd on Westpac board goes paperless with iPads

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

22 hours ago by Doubt on National Botnet Network coming: Earthwave

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

22 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

This story has been voted 10 times in the last 24 hours!

23 hours ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

23 hours ago, Lenovo ThinkPad 3G tablet (32GB)

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

23 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

1 day ago by debsteele on Vic scraps HealthSMART system

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar