Home > Security News > Cisco patches Security Agent flaw
Security News:
EMAIL THIS

Cisco patches Security Agent flaw

By SearchSecurity.com Staff
30 Nov 2005 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Malicious local users could gain escalated privileges by exploiting a security hole in Cisco Systems Inc.'s Security Agent (CSA). But updates are available to fix the problem, the San Jose, Calif.-based networking giant said in an advisory Tuesday.

CSA software provides threat protection for server and desktop computing systems, Cisco said on its Web site. According to the advisory, "A vulnerability exists in CSA agents that can allow a privilege escalation through locally executed software, providing a normal user or attacker with local system level privileges on a Windows workstation or server running managed or standalone CSA 4.5.0 or 4.5.1 agents."

The vulnerability affects:

  • Cisco CSA version 4.5.0 (all builds) managed and standalone agents.
  • Cisco CSA version 4.5.1 (all builds) managed and standalone agents.
  • Cisco CSA version 4.5.0 (build 573) for CallManager
  • Cisco CSA version 4.5.1 (build 628) for CallManager
  • Cisco CSA version 4.5.1 (build 616) for Intelligent Contact Management (ICM), IPCC Enterprise and IPCC Hosted.
  • Cisco CSA version 4.5.0 (build 573) for Cisco Voice Portal (CVP) 3.0 and 3.1.

Cisco said it has made free software available to address this vulnerability. Update installation details are included in the advisory.

Because it can only be exploited locally, Danish vulnerability clearinghouse Secunia has rated the flaw "less critical."

About this time last year, Cisco patched a minor Security Agent flaw that could be exploited by attackers to circumvent the security provided by the host-based intrusion prevention product.

Additionally, earlier this year Cisco fixed a denial-of-service vulnerability in Security Agent that attackers could exploit by sending a crafted IP packet to a Windows workstation or server running Security Agent 4.5.

Tags: Client securityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Client security
DLP technology challenges security costs
Endpoint protection best practices manual: Combating issues, problems
Kaspersky update for SMBs in wake of free Microsoft Security Essentials
Microsoft makes free antivirus software widely available
Security best practices in hotels
Best Antimalware Products
Perimeter defense in the era of the perimeterless network
Microsoft Security Essentials (MSE) shows no vision, expert says
Smart tactics for antivirus and antispyware
Top tactics for endpoint security

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
brute force cracking  (SearchSecurity.com)
buffer overflow  (SearchSecurity.com)
Crash Course: Spyware  (SearchSecurity.com)
email spoofing  (SearchSecurity.com)
phishing  (SearchSecurity.com)
rootkit  (SearchMidmarketSecurity.com)
social engineering  (SearchSecurity.com)
Wired Equivalent Privacy  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts