
Here's what happens and what to do...
By Patrick Gray
Published: 25 April 2003 08:23 BST
A potentially critical vulnerability has been found in Cisco Systems' Secure Access Control Server for Windows servers, which is used to control devices such as routers in large networks.
The buffer overflow glitch may allow an attacker to seize control of the Cisco service when it's running on Windows, according to Cisco. The Unix variant is not affected. Exploitation of the flaw could result in a malicious hacker gaining full control of a target company's security infrastructure, leaving it completely exposed.
"Exploitation of this vulnerability results in a denial of service and can potentially result in system administrator access. Cisco is providing repaired software, and customers are recommended to install patches or upgrade at their earliest opportunity," Cisco said in an advisory released Wednesday. The advisory contains patches for fixing the bug.
The ACS system is used to control routers, firewalls, virtual private networks, voice over IP systems and wireless networks, as well as to provide access policies to users.
An exploit for the vulnerability is not known to be circulating, and ACS servers are usually deployed on network segments with limited physical access.
The flaw was found by researchers at NSFocus Information Technology. The China-based company released an advisory of its own on Thursday.
Administrators of ACS systems block TCP port 2002 until they can deploy Cisco's fix.
Patrick Gray writes for ZDNet Australia.
The following domains are included: Information Risk Assessments Security Policies, Standards and Procedures Human Resource Security Physical & A ...
The ideal candidate will have a skill set to include as many of the following: CCNA or CCNP certified, Routers, Catalyst Switches 29xx, 35xx and ...
My client are looking for a well rounded network engineer with strong general networking skills to work in a Cisco environment on the following ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
July 10th: Just MASH Marketing: The Customer Reference Mashup
Ensure Virtualization is Meeting Your Needs--Read this New White Paper
Mashing it up with Support: Automate, Coordinate and Collaborate with the Incident...
The End of Application Deployment: Virtualised Applications Streamline, Secure and...
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com: Tech teacher shortage, Kangaroo and phones on planes Reader Comments of the Week
Mike Barrett From CIO to consultant: Project manager or salesman? Hard lessons from the coalface…