On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dawn Kawamoto
Posted on ZDNet News: Jul 20, 2006 6:09:00 PM

Networking giant Cisco Systems has fixed several flaws in a security monitoring product meant to protect networks against attacks.

The company outlined the vulnerabilities in its Cisco Security Monitoring Analysis and Response System in an advisory Wednesday. The three vulnerabilities could allow intruders to gain remote access to systems and to glean sensitive information, Cisco said. They relate to the CS-MARS system itself and to the way it interacts with software from Oracle and JBoss.

Cisco said it has patched CS-MARS version 4.2.1 and later, and urged customers to apply all available updates. All previous CS-MARS versions, however, are affected by the flaws.

CS-MARS, which monitors network devices and reports security problems, uses Oracle databases to store sensitive network information, such as authentication credentials for firewalls, routers and IPS devices. Cisco noted that Oracle databases have several built-in default accounts that use well-known passwords. As a result, a malicious attacker could potentially gain access to the information stored in the database.

A malicious attacker could also execute remote code on a CS-MARS appliance and gain administrator privileges via an optional JBoss JMX console. JBoss Web application servers can be used with CS-MARS.

In CS-MARS itself, the problem lies in the command line interface, or CLI, which is designed to allow authenticated administrators to conduct maintenance on their systems. However, several flaws in the CLI could allow an attacker to escalate their privileges to gain root access to a machine, according to a a posting from the SANS Institute's Internet Storm Center.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 2 Talkback(s)
The problem lies with Cisco
or Cisco lies, either way, Cisco is a problem not waiting to bubble over. (Read the rest)
Posted by: Boot_Agnostic Posted on: 07/24/06 You are currently: a Guest | | Terms of Use
When security programs need security..  milal@... | 07/20/06
The problem lies with Cisco  Boot_Agnostic | 07/24/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

  • Here to help you with your Document Management Needs
  • Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
  • To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
  • Produced by
    ZDNet and