navbarPDF
Strip_SecurityNotices

Cisco Security Response: Cisco Secure ACS Weak Session Management Vulnerability

Document ID: 70553

http://www.cisco.com/warp/public/707/cisco-sr-20060623-acs.shtml

Revision 1.2

Last Updated 2006 July 03 1300 UTC (GMT)

For Public Release 2006 June 23 2200 UTC (GMT)


Please provide your feedback on this document.


Contents

Cisco Response
Additional Information
Revision History
Cisco Security Procedures

Cisco Response

This is the Cisco PSIRT response to the statements made by Darren Bounds in his advisory: Cisco Secure ACS Weak Session Management Vulnerability. The original email/advisory is available at

http://www.securityfocus.com/archive/1/438161 leavingcisco.com

and

http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047301.html leavingcisco.com

The attacks described in the report take advantage of a weakness in the default configuration of the Cisco Secure Access Control Server (ACS).

These issues are being tracked by the following Cisco ID numbers (registered customers only)

Cisco PSIRT will update this security response on an "as-needed" basis as additional information on these issues become available.

Additional Information

The following vulnerability affects Cisco Secure ACS for Windows (ACS), the Cisco Secure ACS Solution Engine (ACSE) and Cisco Secure ACS for Unix (CSU). Versions 4.0 and earlier of Cisco Secure ACS and Cisco Secure ACS Solution Engine are affected by this vulnerability. Versions 2.3.6 and earlier of Cisco Secure ACS for Unix are affected by this vulnerability.

The vulnerability is tracked with two different Cisco IDs, for the different platforms.

The following vulnerability affects only Cisco Secure ACS for Windows and Cisco Secure ACS Solution Engine. Versions 4.0 and earlier for Cisco Secure ACS and Cisco Secure ACS Solution Engine are affected by this vulnerability. Cisco Secure for Unix is NOT affected by this vulnerability:

Workarounds

The following mitigations/workarounds should be deployed to mitigate the risks associated with the described vulnerabilities.

Cisco Secure ACS for Unix

In order to mitigate the risks associated with this vulnerability on Cisco Secure ACS for UNIX, Cisco recommends restricting the source IP address to trusted subnets and deploying anti-spoofing techniques:

Cisco Secure ACS for Windows and Cisco Secure ACS Solution Engine

For Cisco Secure ACS for Windows and Cisco Secure ACS Solution Engine to help mitigate the risks of these vulnerabilities, Cisco recommends that customers deploy the following mitigations by using the HTTP GUI:

To prevent spoofed IP packets with the source IP address set to that of the Cisco Secure ACS administrative management station from reaching the Cisco Secure ACS server, utilize anti-spoofing techniques. For more information on utilizing ACLs for anti-spoofing, refer to http://www.cisco.com/warp/public/707/21.pdf and http://www.ietf.org/rfc/rfc2827.txt.

The Unicast Reverse Path Forwarding (Unicast RPF) feature helps to mitigate problems that are caused by forged IP source addresses that are passing through a router. Refer to http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_c/fothersf/scfrpf.htm for more information.

Revision History

Revision 1.2

2006-July-03

Updated Workaround/Cisco Secure ACS for Unix section with additional information.

Revision 1.1

2006-June-28

Added new Cisco Bug ID (CSCse63433) to Cisco response section.

Content added to Additional Information section.

Revision 1.0

2006-June-23

Initial public release.

Cisco Security Procedures

Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt.


Toolbar


Updated: Jul 03, 2006Document ID: 70553