search technology reviews, news, features, group tests
Popular Searches:   windows , free , asus
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Wednesday December 2, 2009 10:53 AM AEST
Skip Navigation LinksPC Authority > News > Cisco patches Clean Access flaws
Cisco patches Clean Access flaws
NEWS

Cisco patches Clean Access flaws

by Shaun Nichols  on Jan 9, 2007
Tags: Cisco | patches | Clean | Access | flaws
Vulnerabilities could allow unauthorised administrator access.
Vulnerabilities could allow unauthorised administrator access.

Cisco Systems has acknowledged a pair of vulnerabilities in its Clean Access networking software that could allow for unauthorised access and viewing of database files. 

Users can remove the vulnerabilities by upgrading their software or by installing a patch, said the company.

Clean Access is a pair of software applications that allows servers to scan any systems that attempt to access a network for required patches and software.

The vulnerabilities effect Shared Secret, a log-on authentication component, and Readable Snapshots, a system for manually backing up databases.

An attacker exploiting the Shared Secret vulnerability could take administrative control over the Clean Access System and have the ability to change settings and preferences, said Cisco.

The Readable Snapshots component could be vulnerable to a 'brute force' attack, according to Cisco.

An attacker who guesses or otherwise finds out the name of the Readable Snapshot file could download and view it without any further authentication.

Security firm Secunia lists both vulnerabilities as 'moderately critical', which ranks third on the company's five-alert scale. 

Users can remove both of the vulnerabilities by upgrading their Clean Access software, said Cisco. Versions 3.4.6.2, 4.0.4, 4.1.0 and later all contain a fix for the vulnerability.

The company has also made a patch available for users who do not want to upgrade.
Copyright © 2009 v3.co.uk
Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Internode starts selling revamped TiVo bundle online
In addition to unmetered downloads, Internode will also sell a 320GB TiVo package for under $700 from its online store.
 
Half of Sony TVs could be 3D capable by 2012
Sony has said up to half of its TVs will be 3D capable by 2012, showing the company's confidence in adding an extra dimension to its products
 
Dutch court guts Mininova
File sharing site Mininova has been ordered by a Dutch court to remove all of its 'pirated' content.
 


 
Intel
 
 
Amazing Dell Coupons now available
 
Discover Apple