Secunia Advisory SA33633Cisco Security Manager Security Bypass Vulnerability
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A vulnerability has been reported in Cisco Security Manager, which can be exploited by malicious people to bypass certain security restrictions. The vulnerability is caused due to the IPS Event Viewer (IEV) opening several TCP ports on the client and server upon execution. This can potentially be exploited to gain access to the IEV MySQL database or IEV server via the open ports on the server and e.g. add, delete, or modify devices added to the IEV. Successful exploitation of this vulnerability requires that the IPS Event Viewer service is enabled. This vulnerability is reported in versions 3.1, 3.1.1, 3.2, and 3.2.1. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||
87 views | ![]() |
| Fedora update for samba | |
109 views | ![]() |
| Debian update for tdiary | |