| PROBLEM: | A vulnerability exists in the Cisco Network Admission Control (NAC) Appliance that can allow an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM). |
| PLATFORM: | The following table lists all Cisco NAC Appliance software versions affected by this vulnerability. NAC Software Release Vulnerable Versions 3.5.x All 3.5.x versions 3.6.x All 3.6.x versions prior to 3.6.4.4 4.0.x All 4.0.x versions prior to 4.0.6 4.1.x All 4.1.x versions prior to 4.1.2 |
| DAMAGE: | An attacker could take complete control of the CAS remotely over the network. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. Successful exploitation of the vulnerability could allow an attacker to take complete control of the CAS remotely over the network. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
10.0 8.3 (AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-267.shtml |
| ORIGINAL BULLETIN: | http://www.cisco.com/en/US/products/products_security_advisory09186a008097bea0.shtml |
| CVE: | CVE-2008-1155 |
[***** Start Cisco Security Advisory Document ID: 100782 *****]
Summary
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
Cisco Security Procedures
A vulnerability exists in the Cisco Network Admission Control (NAC) Appliance that can allow an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM).
Cisco has released free software updates that address this vulnerability.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20080416-nac.shtml.
[Expand all sections] [Collapse all sections]
Affected Products
Details
Vulnerability Scoring Details
Impact
Software Versions and Fixes
Workarounds
Obtaining Fixed Software
Exploitation and Public Announcements
Status of this Notice: FINAL
Distribution
Revision History
[***** End Cisco Security Advisory Document ID: 100782 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org