CERT mailing list archives

Cisco Releases Security Advisory


From: "US-CERT" <US-CERT () public govdelivery com>
Date: Thu, 29 Aug 2013 13:12:27 -0500

US Computer Emergency Readiness Team banner graphic

National Cyber Awareness System:

Cisco Releases Security Advisory [ 
https://www.us-cert.gov/ncas/current-activity/2013/08/29/Cisco-Releases-Security-Advisory ] 08/29/2013 11:19 AM EDT 
Original release date: August 29, 2013

Cisco has released a security advisory to address a vulnerability in Cisco Secure Access Control Server (ACS) versions 
4.0 through 4.2.1.15.  This vulnerability could allow an unauthenticated, remote attacker to execute arbitrary 
commands. The vulnerability is only present when Cisco ACS is configured as a RADIUS server.

Cisco has released software updates that address this vulnerability.

US-CERT encourages administrators of this software to review Cisco Security Advisory 20130828-ACS [ 
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130828-acs ], and follow best practice 
security policies to determine if their organization is affected and the appropriate response.

________________________________________________________________________

This product is provided subject to this Notification [ http://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ http://www.us-cert.gov/privacy/ ] policy.

________________________________________________________________________

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ] 

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: