Section: .. / advisories / cisco /
| /// File Name: |
cisco.00-09-27.ciscosecure_pix |
Description:
|
Cisco Advisory - The Cisco Secure PIX firewall feature "mailguard," which limits SMTP commands to a specified minimum set of commands, can be bypassed. This vulnerability can be exploited to bypass SMTP command filtering. All users of Cisco Secure PIX Firewalls with software versions up to and including 4.4(5), 5.0(3), 5.1(2) and 5.2(1) that provide access to SMTP Mail services are at risk. The IOS Firewall featureset is not affected by either of the above defects.
| | Homepage: | http://www.cisco.com/warp/public/707/sec_incident_response.shtml | | File Size: | 8850 | | Last Modified: | Oct 7 07:41:52 2000 |
| MD5 Checksum: | 11bcea2f363499cdbbbf1465aa2bbe19 |
|
| /// File Name: |
cisco.99-06-10.list_keyword |
Description:
|
cisco.99-06-10.list_keyword
| | File Size: | 8809 | | Last Modified: | Sep 23 05:48:10 1999 |
| MD5 Checksum: | a333d1dd91a211499ca8fdecff238cc3 |
|
| /// File Name: |
cisco.98-05-13.web_cache_control |
Description:
|
Cisco Web Cache Control Protocol Router Vulnerability
| | File Size: | 8676 | | Last Modified: | Sep 23 05:48:10 1999 |
| MD5 Checksum: | 58a95da302289a916024811e40b01c3f |
|
| /// File Name: |
cisco.00-04-19.enable |
Description:
|
Cisco Security Advisory: Cisco Catalyst Enable Password Bypass Vulnerability. Cisco Catalyst software permits unauthorized access to the enable mode in the 5.4(1) release. Once initial access is granted, access can be obtained for the higher level "enable" mode without a password.
| | File Size: | 8597 | | Last Modified: | Apr 23 11:41:38 2000 |
| MD5 Checksum: | 37453138d933754d84c8a8577b6d9cc1 |
|
| /// File Name: |
cisco.01-09-26.pix.smtp |
Description:
|
Cisco Security Advisory - The Cisco Secure PIX firewall feature "mailguard" which limits SMTP commands to a specified minimum set of commands can be bypassed. To exploit this vulnerability, attackers must be able to make connections to an SMTP mail server protected by the PIX Firewall. All users of Cisco Secure PIX Firewalls with software versions 6.0(1), 5.2(5) and 5.2(4) that provide access to SMTP Mail services are at risk.
| | Homepage: | http://www.cisco.com | | File Size: | 8579 | | Last Modified: | Sep 27 08:20:01 2001 |
| MD5 Checksum: | bd7bb40432ce6ef1c3c4e10f11438049 |
|
| /// File Name: |
cisco-ata-186.txt |
Description:
|
Cisco Security Advisory - A vulnerability found in the web interface that comes with the Cisco ATA 186 Analog Telephone Adaptor be used to remotely disclose passwords by retrieving the router config via a specially crafted POST request.
| | Homepage: | http://www.cisco.com/warp/public/707/advisory.html | | File Size: | 8054 | | Last Modified: | May 25 19:53:31 2002 |
| MD5 Checksum: | 75fbb19b5f876c5bdbac50ebafe9176e |
|
| /// File Name: |
cisco.sn5420.txt |
Description:
|
Cisco Security Advisory - Vulnerabilities in Cisco SN 5420 Storage Routers. Two vulnerabilities have been discovered in Cisco SN 5420 Storage Router software release up to and including 1.1(3). One of the vulnerabilities can cause Denial-of-Service attack. The other allows unrestricted low level access to the SN 5420. The vulnerabilities are exploited via TCP ports 514 and 8023.
| | Homepage: | http://www.cisco.com/go/psirt | | File Size: | 7062 | | Last Modified: | Jul 12 09:34:32 2001 |
| MD5 Checksum: | 217a13ba3ed96b040635c794eb890afe |
|
| /// File Name: |
cisco.00-12-06.memleak |
Description:
|
Cisco Security Advisory - Catalyst Memory Leak Vulnerability. A series of failed telnet authentication attempts to the switch can cause the Catalyst Switch to fail to pass traffic or accept management connections until the system is rebooted or a power cycle is performed. All types of telnet authentication are affected, including Kerberized telnet, and AAA authentication.
| | Homepage: | http://www.cisco.com/warp/public/707/sec_incident_response.shtml | | File Size: | 6811 | | Last Modified: | Dec 7 20:01:21 2000 |
| MD5 Checksum: | 9b1539403f297d72a54b5354e0c90da1 |
|
| /// File Name: |
cisco-sa-20031210-ACNS-auth.txt |
Description:
|
Cisco ACNS software prior to 4.2.11 or 5.0.5 contain a remotely exploitable buffer overflow which is triggered by a long password. Affected devices include Content Routers 4400 series, Content Distribution Manager 4600 series, Content Engine 500 and 7300 series, and Content Engine Module for Cisco Routers 2600, 3600 and 3700 series. Workaround is to disable the CE GUI with the command "no gui-server enable".
| | Homepage: | http://www.cisco.com/warp/public/707/cisco-sa-20031210-ACNS-auth.shtml | | File Size: | 6733 | | Last Modified: | Dec 15 04:32:59 2003 |
| MD5 Checksum: | 93625507bb30da8fc0ac7d3d633671b7 |
|
| /// File Name: |
ubr900.txt |
Description:
|
The Cisco UBR 900 series routers allow remote users snmp read access with any community string.
| | Author: | Cushman | | Homepage: | http://www.hack-net.com | | File Size: | 4646 | | Last Modified: | Jan 8 06:51:08 2002 |
| MD5 Checksum: | 6eecb8ee11f2b4a9696a2d3c20fdd922 |
|
| /// File Name: |
Cisco-VPN-Client.txt |
Description:
|
The Cisco VPN 5000 clients for Linux and Solaris contain buffer overflow vulnerabilities that can be used by local users to execute machine code with root privileges.
| | Author: | Niels Heinen | | Homepage: | http://www.ubizen.com | | File Size: | 2945 | | Last Modified: | Sep 19 01:16:25 2002 |
| MD5 Checksum: | c6560559cd40d4e3f9c2d7d3f849c9cb |
|
| /// File Name: |
cisco-3000.txt |
Description:
|
The Cisco VPN3000 gateway lets remote client dictate which maximum MTU to use when sending back ESP frames, regardless of the transmitting capabilities of the physical medium. This can lead to denial of service conditions.
| | Author: | Master Phi | | File Size: | 2052 | | Last Modified: | Jul 12 09:29:41 2002 |
| MD5 Checksum: | 22abcad0808b4ff889974a197cfb521e |
|
|
|
|
|