Network World
Tuesday, December 2, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Cisco issues critical patch for NAC flaw

Cisco issued an urgent security advisory on Wednesday warning users about a critical vulnerability that exists in the company's NAC appliance. The vulnerability allows an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM). An attacker can obtain the shared secret from error logs that are transmitted over the network. Obtaining this information could enable an attacker to gain complete control of the CAS remotely. Cisco has forgone its biannual patching cycle to release this patch, The vulnerability rating is listed as a 10 on the CVSS scale. The patch is available here.

More from Cisco Subnet:

What not to love about Cisco routers as Linux app servers
Cisco partners must grow Cisco reseller business by $20B
Cisco drops plans to beta CCDE practical exam
Cisco's skill shortage math doesn't add up
3Com and Cisco dumb and dumber?
Nexus: Hands on with NX-OS
CCNP lab essentials
Jeff Doyle: Understanding MPLS

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

20 useful sites for Cisco networking professionals
This month's Cisco Subnet giveaways
Network World's IT Buyer's Guide: Cisco products

Subscribe to Network World's Cisco Alert, which includes a weekly digest of all Cisco Subnet items 

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: