Cisco IDS Device Manager 3.1.1 Advisory
From: Andrew.Lopacki@amsouth.comDate: 05/24/02
- Previous message: KF: "Sendmail file locking - PoC"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: da@securityfocus.com, bugtraq@securityfocus.com From: Andrew.Lopacki@amsouth.com Date: Fri, 24 May 2002 13:42:07 -0500
On May 15th I discovered and reported a vulnerability to Cisco about their
Andrew Lopacki
(See attached file: ids.txt.asc)
IDS Device Manager software. On the 17th they issued this advisory to
everyone that downloaded the software. The vulnerability that I reported
was the Cisco IDS Device Manager Arbitrary File Read Access Vulnerability.
I provided the example URL of https://
Cisco TAC and to you guys at SecurityFocus. Cisco now has a fixed version
for IDS Device Manager, now at version 3.1.2. The url for the software is
at http://www.cisco.com/cgi-bin/tablebuild.pl/ids-appsens. The name of the
file is IDSk9-sp.3.1-2-S23.bin. Users that installed IDSk9-sp.3.1-1-S22.bin
will need to uninstall this service pack by typing the command
#IDSk9-sp.3.1-1-S22.bin -U before applying the new service pack.
Intrusion Analyst
AmSouth Bank
Relevant Pages
... Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive ... Security Appliance and Cisco PIX Security Appliances ... Crafted HTTP packet denial of service vulnerability ... Crafted H.323 packet DoS vulnerability ...
(Full-Disclosure)
... Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive ... Security Appliance and Cisco PIX Security Appliances ... Crafted HTTP packet denial of service vulnerability ... Crafted H.323 packet DoS vulnerability ...
(Bugtraq)
... Cisco Security Advisory ... Optical nodes that have the Common Control Cards connected to a Data ... Communications Network and are enabled for Internet Protocol ... A separate vulnerability exists within the Cisco Transport Controller ...
(VulnWatch)
... Cisco Security Advisory ... Optical nodes that have the Common Control Cards connected to a Data ... Communications Network and are enabled for Internet Protocol ... A separate vulnerability exists within the Cisco Transport Controller ...
(Bugtraq)
... Cisco Security Advisory ... Optical nodes that have the Common Control Cards connected to a Data ... Communications Network and are enabled for Internet Protocol ... A separate vulnerability exists within the Cisco Transport Controller ...
(Full-Disclosure)