<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"> 
  <channel>
  <title>ACE Application Control Engine Hot Issues from Cisco TAC</title>
  <link>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</link>
  <description>Hot Issues from Cisco TAC.  Please click the link for complete details.</description>
  <language>en-us</language>

  <managingEditor>wsisk@cisco.com (Wes Sisk)</managingEditor>
  <webMaster>news-at-cisco-rss@cisco.com (Cisco Newsroom)</webMaster>
  <pubDate>Mon, 20 May 2013 10:19:20 EDT</pubDate>
  <lastBuildDate>Mon, 20 May 2013 10:19:20 EDT</lastBuildDate>
  <generator>PERL</generator>

  <docs>http://www.cisco.com/en/US/customer/products/sw/voicesw/ps556/products_tech_note09186a0080937324.shtml</docs>
  <ttl>10080</ttl>

<item>
<title>Cisco ACE Log Retention Denial of Service Vulnerability, Open CSCug78957</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug78957</link>
<description>&lt;b&gt;Symptoms:&lt;/b&gt;
A vulnerability in SSL logging daemon on Cisco ACE could allow an unauthenticated, remote attacker to cause partial DOS condition on the affected 
device.
The vulnerability is due to Cisco ACE not rotating logs from SSL sessions, causing a hard drive to run out of free space. An attacker could exploit this 
vulnerability by sending a large amount of SSL connections to the affected device. An exploit could allow the attacker to exhaust free space on the 
hard drive, causing operations such as configuration and writing configurations on the disk to fail with the following error:
&#39;&#39;write error: No space left on device&#39;&#39;
Additional errors can be seen on the Cisco ACE console.
&lt;br&gt; 
&lt;b&gt;Conditions:&lt;/b&gt;
Running A2(3.6) or later and heavily using the HTTPS management interface.
&lt;br&gt; 
&lt;b&gt;Workaround:&lt;/b&gt;
Contact TAC that can apply a workaround on your module.
 
&lt;b&gt;PSIRT Evaluation:&lt;/b&gt;
The Cisco PSIRT has assigned this bug the following CVSS version 2 score. The Base and Temporal CVSS scores as of the time of evaluation are 
5/4.5:
https://intellishield.cisco.com/security/alertmanager/cvssCalculator.do?dispatch=1&amp;version=2&amp;vector=AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:W/RC:C
CVE ID CVE-2013-1202 has been assigned to document this issue.

Additional details about the vulnerability described here can be found at:
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1202

Additional information on Cisco&#39;s security vulnerability policy can be found at the following URL:
http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html.

</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCug78957</guid>
</item>
<item>
<title>ACE A2(1.0a) rserver shows arp_failed, but probe, arp and access exists, Fixed CSCtc63117</title>
<link>http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtc63117</link>
<description>






&lt;B&gt;Symptom:&lt;/B&gt;

show rserver indicates rserver status s  ARP_FAILED
show arp has mac address for rserver but is LEARNED state instead of RSERVER
you can ping rserver from ace






&lt;br&gt;
&lt;B&gt;Conditions:&lt;/B&gt;

rserver is down for load balancing due  ARP_FAILED state




&lt;br&gt;
&lt;B&gt;Workaround:&lt;/B&gt;

delete rserver and reconfigure



&lt;br&gt;
&lt;B&gt;Further Problem Description:&lt;/B&gt;














</description>
<guid isPermaLink="true">http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;bugId=CSCtc63117</guid>
</item>
   
</channel>
</rss>
