Description
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2005-4494 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the username from the cleartext portion of a RADIUS session, then using the password to log in to another device that uses CS ACS. |
References
History
No history.
Subscriptions
Cisco
Subscribe
Adaptive Security Appliance Software
Subscribe
Pix Asa Ids
Subscribe
Pix Firewall
Subscribe
Pix Firewall 501
Subscribe
Pix Firewall 506
Subscribe
Pix Firewall 515
Subscribe
Pix Firewall 515e
Subscribe
Pix Firewall 520
Subscribe
Pix Firewall 525
Subscribe
Pix Firewall 535
Subscribe
Pix Firewall Software
Subscribe
Secure Access Control Server
Subscribe
Vpn 3000 Concentrator Series Software
Subscribe
Vpn 3001 Concentrator
Subscribe
Vpn 3002 Hardware Client
Subscribe
Vpn 3005 Concentrator Software
Subscribe
Vpn 3015 Concentrator
Subscribe
Vpn 3020 Concentrator
Subscribe
Vpn 3030 Concentator
Subscribe
Vpn 3060 Concentrator
Subscribe
Vpn 3080 Concentrator
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T23:46:05.525Z
Reserved: 2005-12-22T00:00:00.000Z
Link: CVE-2005-4499
No data.
Status : Deferred
Published: 2005-12-22T11:03:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4499
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD