Cisco issued an urgent security advisory on Wednesday warning users about a critical vulnerability that exists in the company’s NAC appliance. The vulnerability allows an attacker to obtain the shared secret that is used between the Cisco Clean Access Server (CAS) and the Cisco Clean Access Manager (CAM). An attacker can obtain the shared secret from error logs that are transmitted over the network. Obtaining this information could enable an attacker to gain complete control of the CAS remotely. Cisco has forgone its biannual patching cycle to release this patch, The vulnerability rating is listed as a 10 on the CVSS scale. The patch is available here.
More from Cisco Subnet:
What not to love about Cisco routers as Linux app serversCisco partners must grow Cisco reseller business by $20BCisco’s skill shortage math doesn’t add up Cisco drops plans to beta CCDE practical exam3Com and Cisco dumb and dumber?
Jeff Doyle: Understanding MPLS
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
20 useful sites for Cisco networking professionals This month’s Cisco Subnet giveawaysNetwork World’s IT Buyer’s Guide: Cisco products
Subscribe to Network World’s Cisco Alert, which includes a weekly digest of all Cisco Subnet items




