Cisco patches Security Manager flaw

By Tom Espiner, ZDNet UK
Friday, January 23, 2009 10:51 AM

Cisco has released an out-of-cycle patch for a vulnerability in its Security Manager product.

The flaw lies in the way Security Manager--which configures firewalls, VPN and intrusion prevention systems (IPS)--interacts with Cisco IPS Event Viewer (IEV). When IEV is launched, it opens several remotely available TCP ports on the Cisco Security Manager server and client. These ports could allow a cybercriminal to gain root access to the IEV database and server, and modify, add or delete devices that the Event Viewer recognizes.

Also, when Cisco IEV is closed, it leaves open ports on the Security Manager server, potentially allowing the server to be compromised.

The vulnerability affects the 3.1, 3.1.1, 3.2 and 3.2.1 versions of Security Manager. Versions 3.0x and 3.2.2 are not affected.

A link to a patch for the vulnerability is provided on the Cisco Web site in security advisory cisco-sa-20090121-csm. One possible workaround is to disable IEV, if it has not been used already, until the system is patched.

Cisco has seen no reports of exploit code in the wild for this vulnerability, or any reports of attacks.

The company normally releases security patches every six months, in March and September. Cisco only releases out-of-cycle patches for flaws it considers serious or critical.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

How to protect yourself from RAID-related UREs

Enterprise Servers & Storage

An Unrecoverable Read Error during a RAID rebuild can ruin an entire day. Scott Lowe talks about UREs and how you can avoid falling victim to this silent threat.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web